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ANNEX 


Proposal for a 


REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL 


laying down rules to prevent and combat child sexual abuse 


(Text with EEA relevance) 
CHAPTER I 
GENERAL PROVISIONS 
Article 1 


Subject matter and scope 


This Regulation lays down uniform rules to prevent and address the misuse of relevant 
information society services for online child sexual abuse in the internal market. 


It establishes, in particular: 


(a) 


(b) 


(c) 


(d) 


(da) 


(e) 


obligations on providers of relevant information society services to minimise the risk 
that their services are misused for online child sexual abuse; 


obligations on providers of hosting services and providers of interpersonal 
communication services to detect and report online child sexual abuse; 


obligations on providers of hosting services to remove or disable access to child 
sexual abuse material on their services; 


obligations on providers of internet access services to prevent users from accessing 
aecess child sexual abuse material; 


obligations on providers of online search engines to delist websites indicating 
specific items of child sexual abuse; 


rules on the implementation and enforcement of this Regulation, including as regards 
the designation and functioning of the competent authorities of the Member States, 
the EU Centre on Child Sexual Abuse established in Article 40 (‘EU Centre’) and 
cooperation and transparency. 


9317/23 FL/ml 2 
ANNEX JAIILIMITE JIN 


3a. 


This Regulation shall apply to providers of relevant information society services offering 
such services in the Union, irrespective of their place of main establishment. 


This Regulation shall not affect the rules laid down by the following legal acts: 


(a) Directive 2011/93/EU on combating the sexual abuse and sexual exploitation of 
children and child pornography, and replacing Council Framework Decision 
2004/68/JHA; 


(b) Directive 2000/31/EC and Regulation (EU) .../... [on a Single Market For Digital 
Services (Digital Services Act) and amending Directive 2000/3 1/EC]; 


(ba) Regulation (EU) 2022/... of ... on contestable and fair markets in the digital 
sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital 
Markets Act); 


(c) Directive 2010/13/EU; 


(d) Regulation (EU) 2016/679, Directive 2016/680, Regulation (EU) 2018/1725, and, 
subject to paragraph 4 of this Article, Directive 2002/58/EC; 


(e) Regulation (EU) 2021/784 of the European Parliament and of the Council of 29 
April 2021 on addressing the dissemination of terrorist content online. 


This Regulation shall not have the effect of modifying the obligation to respect the 
rights, freedoms and principles referred to in Article 6 TEU and shall apply without 
prejudice to fundamental principles relating to the right for respect to private life and 
family life and to freedom of expression and information. ! 


This Regulation limits the exercise of the rights and obligations provided for in 5(1) and 
(3) and Article 6(1) of Directive 2002/58/EC insofar as necessary for the execution of the 
detection orders issued in accordance with Section 2 of Chapter + II of this Regulation. 


Wording copied from Art. 1(4) of TCO Regulation with an additional reference to the right to 
private life. 
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Article 2 


Definitions 


For the purpose of this Regulation, the following definitions apply: 


(a) 


(b) 


(c) 


(d) 


(e) 


(f) 


‘hosting service’ means an information society service as defined in Article 2, point (f), 
third indent, of Regulation (EU) .../... fon a Single Market For Digital Services (Digital 
Services Act) and amending Directive 2000/3 1/EC]; 


‘number-independent interpersonal communications service’ means a publicly available 
service as defined in Article 2, point 7 5, of Directive (EU) 2018/1972, including services 
which enable direct interpersonal and interactive exchange of information merely as a 
minor ancillary feature that is intrinsically linked to another service; 2 


‘software application’ means a digital product or service as defined in Article 2, point 13, 
of Regulation (EU) .../... [on contestable and fair markets in the digital sector (Digital 
Markets Act); 


‘software application store’ means a service as defined in Article 2, point 12, of Regulation 
(EU) .../... [on contestable and fair markets in the digital sector (Digital Markets Act)] ; 


‘internet access service’ means a service as defined in Article 2(2), point 2, of Regulation 
(EV) 2015/2120 of the European Parliament and of the Council3; 


‘relevant information society services’ means all of the following services: 
(i) a hosting service; 

(ii) an interpersonal communications service; 

(111) a software applications store; 

(iv) an internet access service; 


(v) online search engines. 


PCY comment: See Article 2(1) of the Temporary Regulation (EU) 2021/1232. Many 
opinions have been expressed that the scope should not include regular telecom providers but 
be limited to the number-independent service providers. The draft opinion of the IMCO 
Committee in the EP is also going in this direction and provides elaborate additions to recital 
Ds 


Regulation (EU) 2015/2120 of the European Parliament and of the Council of 25 November 
2015 laying down measures concerning open internet access and amending Directive 
2002/22/EC on universal service and users’ rights relating to electronic communications 
networks and services and Regulation (EU) No 531/2012 on roaming on public mobile 
communications networks within the Union (OJ L 310, 26.11.2015, p. 1-18). 
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(g) 


‘to offer services in the Union’ means to offer services in the Union as defined in Article 2, 
point (d), of Regulation (EU) .../... [on a Single Market For Digital Services (Digital 
Services Act) and amending Directive 2000/3 1/EC]; 


‘user’ means any natural or legal person who uses a relevant information society service; 
‘child’ means any natural person below the age of 18 years;4 


‘chid user means—a_natural person whe-uses—_a relevant information society service_and 


(I) 


(m) 


(n) 


(0) 


(p) 


whos natural person belowthe age of 17 years:5 


‘micro, small or medium-sized enterprise’ means an enterprise as defined in Commission 
Recommendation 2003/361 concerning the definition of micro, small and medium-sized 
enterprises®; 


‘child sexual abuse material’ means: material constituting child pormmography or 
pornographic performance as defined in Article 2, points (c) and (e), respectively, of 
Directive 2011/93/EU; 


‘known child sexual abuse material’ means potential child sexual abuse material detected 
using the indicators contained in the database of indicators referred to in Article 44(1), 
point (a); 


‘new child sexual abuse material’ means potential child sexual abuse material detected 
using the indicators contained in the database of indicators referred to in Article 44(1), 
point (b); 


‘solicitation of children’ means the solicitation of children for sexual purposes as referred 
to in Article 6 of Directive 2011/93/EU; 


‘online child sexual abuse’ means the online dissemination of child sexual abuse material 
and the solicitation of children; 


PCY comment: The term child appears 511 times in the whole proposal including in the 
explanatory statements. The PCY is of the view that the term child can be used where it does 
not lead to problematic incompatibilities between the exercise of powers by Member States, 
for instance when it comes to the notice mechanism being developed under Article 12. 


PCY comment: It seems superfluous to define child user since child is already defined in 
point (1) (in document 14143/22 the age was set at 18). Furthermore, the term child user 
appears in Articles 3(2)(e)(11) and (111), 4(3), 6(1)(b) and (c) and 7(7), i.e on six occasions. As 
those Articles and paragraphs are discussed, alternative wording should be developed. 


Commission Recommendation of 6 May 2003 concerning the definition of micro, small and 
medium-sized enterprises (OJ L 124, 20.5.2003, p. 36-41). 
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(q) 


(r) 


(s) 


(t) 


(u) 


(v) 


(w) 


(x) 


‘child sexual abuse offences’ means offences as defined in Articles 3 to 7 of Directive 
2011/93/EU; 


‘recommender system’ means the system as defined in Article 2, point (0), of Regulation 
(EU) .../... fon a Single Market For Digital Services (Digital Services Act) and amending 
Directive 2000/3 1/EC]; 


‘content data’ means data as defined in Article 2, point 10, of Regulation (EU) ... [on 
European Production and Preservation Orders for electronic evidence in criminal matters 
(.../... e-evidence Regulation)]; 


‘content moderation’ means the activities as defined in Article 2, point (p), of Regulation 
(EU) .../... fon a Single Market For Digital Services (Digital Services Act) and amending 
Directive 2000/3 1/EC]; 


‘Coordinating Authority of establishment’ means the Coordinating Authority for child 
sexual abuse issues designated in accordance with Article 25 by the Member State where 
the provider of information society services has its main establishment or, where 
applicable, where its legal representative resides or is established; 


‘terms and conditions’ means terms and conditions as defined in Article 2, point (q), of 
Regulation (EU) .../... fon a Single Market For Digital Services (Digital Services Act) and 
amending Directive 2000/3 1/EC]; 


‘main establishment’ means the head office or registered office of the provider of relevant 
information society services within which the principal financial functions and operational 
control are exercised; 


‘online search engine’ means an intermediary service as defined in Article 3, point (j), 
of Regulation (EU) .../... [on a Single Market For Digital Services (Digital Services 
Act) and amending Directive 2000/31/EC]. 
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CHAPTER II 


OBLIGATIONS OF PROVIDERS OF RELEVANT INFORMATION SOCIETY SERVICES 
TO PREVENT AND COMBAT ONLINE CHILD SEXUAL ABUSE 


Section 1 
Risk assessment and mitigation obligations 


Article 3 
Risk assessment 


1. Providers of hosting services and providers of interpersonal communications services shall 
identify, analyse and assess, for each such service that they offer, the risk of use of the 
service for the purpose of online child sexual abuse. 


2: When carrying out a risk assessment, the provider shall take into account, in particular: 


(a) any previously identified instances of use of its services for the purpose of online 
child sexual abuse; 


(b) the existence and implementation by the provider of a policy and the availability of 
functionalities to address the risk referred to in paragraph 1, including through the 
following: 


- prohibitions and restrictions laid down in the terms and conditions; 
- measures taken to enforce such prohibitions and restrictions; 
- functionalities enabling age verification; 


- functionalities enabling users to flag online child sexual abuse to the provider 
through tools that are easily accessible and age-appropriate; 


(c) the manner in which users use the service and the impact thereof on that risk; 


(d) the manner in which the provider designed and operates the service, including the 
business model, governance and relevant systems and processes, and the impact 
thereof on that risk; 
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(e) with respect to the risk of solicitation of children: 
(i) the extent to which the service is used or is likely to be used by children; 


(ii) where the service is used by children, the different age groups of the child 
users and the risk of solicitation of children in relation to those age groups; 


(iii) the availability of functionalities creating or reinforcing the risk of solicitation 
of children, including the following functionalities: 


— enabling users to search for other users and, in particular, for adult users 
to search for child users; 


— enabling users to establish contact with other users directly, in particular 
through private communications; 


- enabling users to share images or videos with other users, in particular 
through private communications. 


The provider may request the EU Centre to perform an analysis of representative, 
anonymized data samples to identify potential online child sexual abuse, to support the risk 
assessment. 


The costs incurred by the EU Centre for the performance of such an analysis shall be borne 
by the requesting provider. However, the EU Centre shall bear those costs where the 
provider is a micro, small or medium-sized enterprise, provided the request is reasonably 
necessary to support the risk assessment. 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to supplement this Regulation with the necessary detailed rules on the 
determination and charging of those costs and the application of the exemption for micro, 
small and medium-sized enterprises. 


The provider shall carry out the first risk assessment by /Date of application of this 
Regulation + 3 months] or, where the provider did not offer the service in the Union by 
[Date of application of this Regulation], by three months from the date at which the 
provider started offering the service in the Union. 


Subsequently, the provider shall update the risk assessment where necessary and at least 
once every three years from the date at which it last carried out or updated the risk 
assessment. However: 


(a) fora service which is subject to a detection order issued in accordance with Article 7, 
the provider shall update the risk assessment at the latest te four months before the 
expiry of the period of application of the detection order; 
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(b) the Coordinating Authority of establishment may require the provider to update the 
risk assessment at a reasonable earlier date than the date referred to in the second 
subparagraph, where there is evidence indicating a possible substantial change in the 
risk that the service is used for the purpose of online child sexual abuse. 


The risk assessment shall include an assessment of any potential remaining risk that, after 
taking the mitigation measures pursuant to Article 4, the service is used for the purpose of 
online child sexual abuse. 


The Commission, in cooperation with Coordinating Authorities and the EU Centre and 
after having conducted a public consultation, may issue guidelines on the application of 
paragraphs 1 to 5, having due regard in particular to relevant technological developments 
and to the manners in which the services covered by those provisions are offered and used. 


Article 4 
Risk mitigation 


Providers of hosting services and providers of interpersonal communications services shall 
take reasonable mitigation measures, tailored to the risk identified pursuant to Article 3, to 
minimise that risk. Such measures shall include some or all of the following: 


(a) adapting, through appropriate technical and operational measures and staffing, the 
provider’s content moderation or recommender systems, its decision-making 
processes, the operation or functionalities of the service, or the content or 
enforcement of its terms and conditions; 


(b) reinforcing the provider’s internal processes or the internal supervision of the 
functioning of the service; 


(c) initiating or adjusting cooperation, in accordance with competition law, with other 
providers of hosting services or providers of interpersonal communication services, 
public authorities, civil society organisations or, where applicable, entities awarded 
the status of trusted flaggers in accordance with Article 19 of Regulation (EU) .../... 
[on a Single Market For Digital Services (Digital Services Act) and amending 
Directive 2000/3 1/EC] . 


The mitigation measures shall be: 
(a) effective in mitigating the identified risk; 


(b) targeted and proportionate in relation to that risk, taking into account, in particular, 
the seriousness of the risk as well as the provider’s financial and technological 
capabilities and the number of users; 
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(c) applied in a diligent and non-discriminatory manner, having due regard, in all 
circumstances, to the potential consequences of the mitigation measures for the 
exercise of fundamental rights of all parties affected; 


(d) introduced, reviewed, discontinued or expanded, as appropriate, each time the risk 
assessment is conducted or updated pursuant to Article 3(4), within three months 
from the date referred to therein. 


Providers of interpersonal communications services that have identified, pursuant to the 
risk assessment conducted or updated in accordance with Article 3, a risk of use of their 
services for the purpose of the solicitation of children, shall take the necessary age 
verification and age assessment measures to reliably identify child users on their services, 
enabling them to take the mitigation measures. 


Providers of hosting services and providers of interpersonal communications services shall 
clearly describe in their terms and conditions the mitigation measures that they have taken. 
That description shall not include information that may reduce the effectiveness of the 
mitigation measures. 


The Commission, in cooperation with Coordinating Authorities and the EU Centre and 
after having conducted a public consultation, may issue guidelines on the application of 
paragraphs 1, 2, 3 and 4, having due regard in particular to relevant technological 
developments and in the manners in which the services covered by those provisions are 
offered and used. 


Article 5 
Risk reporting 


Providers of hosting services and providers of interpersonal communications services shall 
transmit, by three months from the date referred to in Article 3(4), to the Coordinating 
Authority of establishment a report specifying the following: 


(a) the process and the results of the risk assessment conducted or updated pursuant to 
Article 3, including the assessment of any potential remaining risk referred to in 
Article 3(5); 


(b) any mitigation measures taken pursuant to Article 4. 


Within three months after receiving the report, the Coordinating Authority of establishment 
shall assess it and determine, on that basis and taking into account any other relevant 
information available to it, whether the risk assessment has been carried out or updated and 
the mitigation measures have been taken in accordance with the requirements of Articles 3 
and 4. 
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Where necessary for that assessment, that Coordinating Authority may require further 
information from the provider, within a reasonable time period set by that Coordinating 
Authority. That time period shall not be longer than two weeks. 


The time period referred to in the -first subparagraph paragraph 2 of this Article_shall be 
suspended until that additional information is provided. 


Without prejudice to Articles 7 and 27 to 29, where the requirements of Articles 3 and 4 
have not been met, that Coordinating Authority shall require the provider to re-conduct or 
update the risk assessment or to introduce, review, discontinue or expand, as applicable, 
the mitigation measures, within a reasonable time period set by that Coordinating 
Authority. That time period shall not be longer than one month. 


Providers shall, when transmitting the report to the Coordinating Authority of 
establishment in accordance with paragraph 1, transmit the report also to the EU Centre. 


Providers shall, upon request, transmit the report to the providers of software application 
stores, insofar as necessary for the assessment referred to in Article 6(2). Where necessary, 
they may remove confidential information from the reports. 


Article 6 
Obligations for software application stores 
Providers of software application stores shall: 


(a) make reasonable efforts to assess, where possible together with the providers of 
software applications, whether each service offered through the software applications 
that they intermediate presents a risk of being used for the purpose of the solicitation 
of children; 


(b) take reasonable measures to prevent child users from accessing the software 
applications in relation to which they have identified a significant risk of use of the 
service concerned for the purpose of the solicitation of children; 


(c) take the necessary age verification and age assessment measures to reliably identify 
child users on their services, enabling them to take the measures referred to in point 


(b). 


In assessing the risk referred to in paragraph 1, the provider shall take into account all the 
available information, including the results of the risk assessment conducted or updated 
pursuant to Article 3. 
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Providers of software application stores shall make publicly available information 
describing the process and criteria used to assess the risk and describing the measures 
referred to in paragraph 1. That description shall not include information that may reduce 
the effectiveness ofthe-assessment of those measures. 


The Commission, in cooperation with Coordinating Authorities and the EU Centre and 
after having conducted a public consultation, may issue guidelines on the application of 
paragraphs 1, 2 and 3, having due regard in particular to relevant technological 
developments and to the manners in which the services covered by those provisions are 
offered and used. 


Section 2 
Detection obligations 


Article 7 
Issuance of detection orders 


The Coordinating Authority of establishment shall have the power to request the competent 
judicial authority of the Member State that designated it or another independent 
administrative authority of that Member State to issue a detection order requiring a 
provider of hosting services or a provider of interpersonal communications services under 
the jurisdiction of that Member State to take the measures specified in Article 10 to detect 
online child sexual abuse on a specific service. 


The Coordinating Authority of establishment shall, before requesting the issuance of a 
detection order, carry out the investigations and assessments necessary to determine 
whether the conditions of paragraph 4 have been met. 


To that end, it may, where appropriate, require the provider to submit the necessary 
information, additional to the report and the further information referred to in Article 5(1) 
and (3), respectively, within a reasonable time period set by that Coordinating Authority, or 
request the EU Centre, another public authority or relevant experts or entities to provide 
the necessary additional information. 


Where the Coordinating Authority of establishment takes the preliminary view that the 
conditions of paragraph 4 have been met, it shall: 


(a) establish a draft request for the issuance of a detection order, specifying the main 
elements of the content of the detection order it intends to request and the reasons for 
requesting it; 


(b) submit the draft request to the provider and the EU Centre; 


(c) afford the provider an opportunity to comment on the draft request, within a 
reasonable time period set by that Coordinating Authority; 


(d) invite the EU Centre to provide its opinion on the draft request, within a time period 
of four weeks from the date of receiving the draft request. 
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Where, having regard to the comments of the provider and the opinion of the EU Centre, 
that Coordinating Authority continues to be of the view that the conditions of paragraph 4 
have met, it shall re-submit the draft request, adjusted where appropriate, to the provider. 
In that case, the provider shall do all of the following, within a reasonable time period set 
by that Coordinating Authority: 


(a) draft an implementation plan setting out the measures it envisages taking to execute 
the intended detection order, including detailed information regarding the envisaged 
technologies and safeguards; 


(b) where the draft implementation plan concerns an intended detection order concerning 
the solicitation of children other than the renewal of a previously issued detection 
order without any substantive changes, conduct a data protection impact assessment 
and a prior consultation procedure as referred to in Articles 35 and 36 of Regulation 
(EU) 2016/679, respectively, in relation to the measures set out in the 
implementation plan; 


(c) where point (b) applies, or where the conditions of Articles 35 and 36 of Regulation 
(EU) 2016/679 are met, adjust the draft implementation plan, where necessary in 
view of the outcome of the data protection impact assessment and in order to take 
into account the opinion of the data protection authority provided in response to the 
prior consultation; 


(d) submit to that Coordinating Authority the implementation plan, where applicable 
attaching the opinion of the competent data protection authority and specifying how 
the implementation plan has been adjusted in view of the outcome of the data 
protection impact assessment and of that opinion. 


Where, having regard to the implementation plan of the provider and the opinion of the 
data protection authority, that Coordinating Authority continues to be of the view that the 
conditions of paragraph 4 have met, it shall submit the request for the issuance of the 
detection, adjusted where appropriate, to the competent judicial authority or independent 
administrative authority. It shall attach the implementation plan of the provider and the 
opinions of the EU Centre and the data protection authority to that request. 


The Coordinating Authority of establishment shall request the issuance of the detection 
order, and the competent judicial authority or independent administrative authority shall 
issue the detection order where it considers that the following conditions are met: 


(a) there is evidence of a significant risk of the service being used for the purpose of 
online child sexual abuse, within the meaning of paragraphs 5, 6 and 7, as applicable; 


(b) the reasons for issuing the detection order outweigh negative consequences for the 
rights and legitimate interests of all parties affected, having regard in particular to the 
need to ensure a fair balance between the fundamental rights of those parties. 
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When assessing whether the conditions of the first subparagraph have been met, account 
shall be taken of all relevant facts and circumstances of the case at hand, in particular: 


(a) the risk assessment conducted or updated and any mitigation measures taken by the 
provider pursuant to Articles 3 and 4, including any mitigation measures introduced, 
reviewed, discontinued or expanded pursuant to Article 5(4) where applicable; 


(b) any additional information obtained pursuant to paragraph 2 or any other relevant 
information available to it, in particular regarding the use, design and operation of 
the service, regarding the provider’s financial and technological capabilities and size 
and regarding the potential consequences of the measures to be taken to execute the 
detection order for all other parties affected; 


(c) the views and the implementation plan of the provider submitted in accordance with 
paragraph 3; 


(d) the opinions of the EU Centre and of the data protection authority submitted in 
accordance with paragraph 3. 


As regards the second subparagraph, point (d), where that Coordinating Authority 
substantially deviates from the opinion of the EU Centre, it shall inform the EU Centre and 
the Commission thereof, specifying the points at which it deviated and the main reasons 
for the deviation. 


As regards detection orders concerning the dissemination of known child sexual abuse 
material, the significant risk referred to in paragraph 4, first subparagraph, point (a), shall 
be deemed to exist where the following conditions are met: 


(a) it is likely, despite any mitigation measures that the provider may have taken or will 
take, that the service is used, to an appreciable extent for the dissemination of known 
child sexual abuse material; 


(b) there is evidence of the service, or of a comparable service if the service has not yet 
been offered in the Union at the date of the request for the issuance of the detection 
order, having been used in the past 12 months and to an appreciable extent for the 
dissemination of known child sexual abuse material. 


As regards detection orders concerning the dissemination of new child sexual abuse 
material, the significant risk referred to in paragraph 4, first subparagraph, point (a), shall 
be deemed to exist where the following conditions are met: 


(a) itis likely that, despite any mitigation measures that the provider may have taken or 
will take, the service is used, to an appreciable extent, for the dissemination of new 
child sexual abuse material; 
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(b) there is evidence of the service, or of a comparable service if the service has not yet 
been offered in the Union at the date of the request for the issuance of the detection 
order, having been used in the past 12 months and to an appreciable extent, for the 
dissemination of new child sexual abuse material; 


(c) for services other than those enabling the live transmission of pornographic 
performances as defined in Article 2, point (e), of Directive 2011/93/EU: 


(1) a detection order concerning the dissemination of known child sexual abuse 
material has been issued in respect of the service; 


(2) the provider submitted a significant number of reports concerning known child 
sexual abuse material, detected through the measures taken to execute the 
detection order referred to in point (1), pursuant to Article 12. 


As regards detection orders concerning the solicitation of children, the significant risk 
referred to in paragraph 4, first subparagraph, point (a), shall be deemed to exist where the 
following conditions are met: 


(a) the provider qualifies as a provider of interpersonal communication services; 


(b) it is likely that, despite any mitigation measures that the provider may have taken or 
will take, the service is used, to an appreciable extent, for the solicitation of children; 


(c) there is evidence of the service, or of a comparable service if the service has not yet 
been offered in the Union at the date of the request for the issuance of the detection 
order, having been used in the past 12 months and to an appreciable extent, for the 
solicitation of children. 


The detection orders concerning the solicitation of children shall apply only to 
interpersonal communications where one of the users is a child usee?. 


The Coordinating Authority of establishment when requesting the issuance of detection 
orders, and the competent judicial or independent administrative authority when issuing 
the detection order, shall target and specify it in such a manner that the negative 
consequences referred to in paragraph 4, first subparagraph, point (b), remain limited to 
what is strictly necessary to effectively address the significant risk referred to in point (a) 
thereof. 


PCY comment: The PCY concludes that both the term ‘child’ and ‘child user’ as defined at 
present will cause difficult issues requiring further work. 
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To that aim, they shall take into account all relevant parameters, including the availability 
of sufficiently reliable detection technologies in that they limit to the maximum extent 
possible the rate of errors regarding the detection and their suitability and effectiveness for 
achieving the objectives of this Regulation, as well as the impact of the measures on the 
rights of the users affected, and require the taking of the least intrusive measures, in 
accordance with Article 10, from among several equally effective measures. 


In particular, they shall ensure that: 


(a) where that risk is limited to an identifiable part or component of a service, the 
required measures are only applied in respect of that part or component; 


(b) where necessary, in particular to limit such negative consequences, effective and 
proportionate safeguards additional to those listed in Article 10(4), (5) and (6) are 
provided for; 


(c) subject to paragraph 9, the period of application remains limited to what is strictly 
necessary. 


The competent judicial authority or independent administrative authority shall specify in 
the detection order the period during which it applies, indicating the start date and the end 
date. 


The start date shall be set taking into account the time reasonably required for the provider 
to take the necessary measures to prepare the execution of the detection order. It shall not 
be earlier than three months from the date at which the provider received the detection 
order and not be later than 12 months from that date. 


The period of application of detection orders concerning the dissemination of known or 
new child sexual abuse material shall not exceed 24 months and that of detection orders 
concerning the solicitation of children shall not exceed 12 months. 


Article 8 
Additional rules regarding detection orders 


The competent judicial authority or independent administrative authority shall issue the 
detection orders referred to in Article 7 using the template set out in Annex I. Detection 
orders shall include: 


(a) information regarding the measures to be taken to execute the detection order, 
including the indicators to be used and the safeguards to be provided for, including 
the reporting requirements set pursuant to Article 9(3) and, where applicable, any 
additional safeguards as referred to in Article 7(8); 
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(b) identification details of the competent judicial authority or the independent 
administrative authority issuing the detection order and authentication of the 
detection order by that judicial or independent administrative authority; 


(c) the name of the provider and, where applicable, its legal representative; 


(d) the specific service in respect of which the detection order is issued and, where 
applicable, the part or component of the service affected as referred to in Article 7(8); 


(e) whether the detection order issued concerns the dissemination of known or new child 
sexual abuse material or the solicitation of children; 


(f) the start date and the end date of the detection order; 


(g) a sufficiently detailed statement of reasons explaining why the detection order is 
issued; 


(h) areference to this Regulation as the legal basis for the detection order; 


(i) the date, time stamp and electronic signature of the judicial or independent 
administrative authority issuing the detection order; 


(j) easily understandable information about the redress available to the addressee of the 
detection order, including information about redress to a court and about the time 
periods applicable to such redress. 


The competent judicial authority or independent administrative authority issuing the 
detection order shall address it to the main establishment of the provider or, where 
applicable, to its legal representative designated in accordance with Article 24. 


The detection order shall be transmitted to the provider’s point of contact referred to in 
Article 23(1), to the Coordinating Authority of establishment and to the EU Centre, 
through the system established in accordance with Article 39(2). 


The detection order shall be drafted transmitted in any of the official languages declared 
by the provider pursuant to Article 23(3). 


The order may also be transmitted in any of the official languages of the Member 
State autherity issuing the order, provided that it is accompanied by a translation of 
at least the most important elements necessary for the execution of the order into any 
of the official languages declared by the provider in accordance with article 23(3). 
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If the provider cannot execute the detection order because it contains manifest errors or 
does not contain sufficient information for its execution, the provider shall, without undue 
delay, request the necessary clarification to the Coordinating Authority of establishment, 
using the template set out in Annex II. 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to amend Annexes I and II where necessary to improve the templates in view of 
relevant technological developments or practical experiences gained. 


Article 9 
Redress, information, reporting and modification of detection orders 


Providers of hosting services and providers of interpersonal communications services. that 
have received a detection order, as well as users affected by the measures taken to execute 
it, shall have a right to effective redress. That right shall include the right to challenge the 
detection order before the courts of the Member State of the competent judicial authority 
or independent administrative authority that issued the detection order. 


When the detection order becomes final, the competent judicial authority or independent 
administrative authority that issued the detection order shall, without undue delay, transmit 
a-copythereofte inform the Coordinating Authority of establishment. The Coordinating 
Authority of establishment shall then, without undue delay, transmit a copy thereef of the 
detection order to all other Coordinating Authorities through the system established in 
accordance with Article 39(2). 


For the purpose of the first subparagraph, a detection order shall become final upon the 
expiry of the time period for appeal where no appeal has been lodged in accordance with 
national law or upon confirmation of the detection order following an appeal. 


Where the period of application of the detection order exceeds 12 months, or six months in 
the case of a detection order concerning the solicitation of children, the Coordinating 
Authority of establishment shall require the provider to report to it on the execution of the 
detection order at least once, halfway through the period of application. 


Those reports shall include a detailed description of the measures taken to execute the 
detection order, including the safeguards provided, and information on the functioning in 
practice of those measures, in particular on their effectiveness in detecting the 
dissemination of known or new child sexual abuse material or the solicitation of children, 
as applicable, and on the consequences of those measures for the rights and legitimate 
interests of all parties affected. 
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In respect of the detection orders that the competent judicial authority or independent 
administrative authority issued at its request, the Coordinating Authority of establishment 
shall, where necessary and in any event following reception of the reports referred to in 
paragraph 3, assess whether any substantial changes to the grounds for issuing the 
detection orders occurred and, in particular, whether the conditions of Article 7(4) continue 
to be met. In that regard, it shall take account of additional mitigation measures that the 
provider may take to address the significant risk identified at the time of the issuance of the 
detection order. 


That Coordinating Authority shall request to the competent judicial authority or 
independent administrative authority that issued the detection order the modification or 
revocation of such order, where necessary in the light of the outcome of that assessment. 
The provisions of this Section shall apply to such requests, mutatis mutandis. 


Article 10 
Technologies and safeguards 


Providers of hosting services and providers of interpersonal communication services that 
have received a detection order shall execute it by installing and operating technologies to 
detect the dissemination of known or new child sexual abuse material or the solicitation of 
children, as applicable, using the corresponding indicators provided by the EU Centre in 
accordance with Article 46. 


The provider shall be entitled to acquire, install and operate, free of charge, technologies 
made available by the EU Centre in accordance with Article 50(1), for the sole purpose of 
executing the detection order. The provider shall not be required to use any specific 
technology, including those made available by the EU Centre, as long as the requirements 
set out in this Article are met. The use of the technologies made available by the EU Centre 
shall not affect the responsibility of the provider to comply with those requirements and for 
any decisions it may take in connection to or as a result of the use of the technologies. 


The technologies shall be: 


(a) effective in detecting the dissemination of known or new child sexual abuse material 
or the solicitation of children, as applicable; 


(b) not be able to extract any other information from the relevant communications than 
the information strictly necessary to detect, using the indicators referred to in 
paragraph 1, patterns pointing to the dissemination of known or new child sexual 
abuse material or the solicitation of children, as applicable; 


(c) in accordance with the state of the art in the industry and the least intrusive in terms 
of the impact on the users’ rights to private and family life, including the 
confidentiality of communication, and to protection of personal data; 


(d) sufficiently reliable, in that they limit to the maximum extent possible the rate of 
errors regarding the detection. 
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The provider shall: 


(a) 


(b) 


(c) 


(d) 


(e) 


(f) 


take all the necessary measures to ensure that the technologies and indicators, as well 
as the processing of personal data and other data in connection thereto, are used for 
the sole purpose of detecting the dissemination of known or new child sexual abuse 
material or the solicitation of children, as applicable, insofar as strictly necessary to 
execute the detection orders addressed to them; 


establish effective internal procedures to prevent and, where necessary, detect and 
remedy any misuse of the technologies, indicators and personal data and other data 
referred to in point (a), including unauthorized access to, and unauthorised transfers 
of, such personal data and other data; 


ensure regular human oversight as necessary to ensure that the technologies operate 
in a sufficiently reliable manner and,-where-necessaryin_particular whenpotential 
errors-and potential solicitation of children are detected _humaninterventions; 


establish and operate an accessible, age-appropriate and user-friendly mechanism 
that allows users to submit to it, within a reasonable timeframe, complaints about 
alleged infringements of its obligations under this Section, as well as any decisions 
that the provider may have taken in relation to the use of the technologies, including 
the removal or disabling of access to material provided by users, blocking the users’ 
accounts or suspending or terminating the provision of the service to the users, and 
process such complaints in an objective, effective and timely manner; 


inform the Coordinating Authority, at the latest one month before the start date 
specified in the detection order, on the implementation of the envisaged measures set 
out in the implementation plan referred to in Article 7(3); 


regularly review the functioning of the measures referred to in points (a), (b), (c) and 
(d) of this paragraph and adjust them where necessary to ensure that the requirements 
set out therein are met, as well as document the review process and the outcomes 
thereof and include that information in the report referred to in Article 9(3). 


The provider shall inform users in a clear, prominent and comprehensible way of the 
following: 


(a) 


the fact that it operates technologies to detect online child sexual abuse to execute the 
detection order, the ways in which it operates those technologies and the impact on 
the confidentiality of users’ communications; 
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Will be included in a recital. 
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(b) the fact that it is required to report potential online child sexual abuse to the EU 
Centre in accordance with Article 12; 


(c) the users’ right of judicial redress referred to in Article 9(1) and their rights to submit 
complaints to the provider through the mechanism referred to in paragraph 4, point 
(d) and to the Coordinating Authority in accordance with Article 34. 


The provider shall not provide information to users that may reduce the effectiveness of the 
measures to execute the detection order. 


6. Where a provider detects potential online child sexual abuse through the measures taken to 
execute the detection order, it shall inform the users concerned without undue delay, after 
Eurepelerthe national law enforcement authority of a Member State that received the 
report pursuant to Article 48 has confirmed that the information to the users would not 
interfere with activities for the prevention, detection, investigation and prosecution of child 
sexual abuse offences. 


Article 11 
Guidelines regarding detection obligations 


The Commission, in cooperation with the Coordinating Authorities and the EU Centre and after 
having conducted a public consultation, may issue guidelines on the application of Articles 7 to 10, 
having due regard in particular to relevant technological developments and the manners in which 
the services covered by those provisions are offered and used. 


Section 3 
Reporting obligations 
Article 12 
Reporting obligations 


ie Where a provider of hosting services or a provider of interpersonal communications 
services becomes aware in any manner other than through a removal order issued in 
accordance with this Regulation of any information indicating that indicate potential 
online child sexual abuse on its services, it shall promptly submit a report thereon to the 
EU Centre in accordance with Article 13. It shall do so through the system established in 
accordance with Article 39(2). 
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Where the provider submits a report pursuant to paragraph 1, it shall inform the user 
concerned, in accordance with the following sub-paragraphs providing information on 
the main content of the report—enthe-mannerin—which-the provider has become aware-of 
the _ potential chHd sexual abuse concernedonthe follow-up _siven tothe reportinsefaras 
suchformationisavaiable tothe previder and on the user’s possibilities of redress, 
including on the right to submit complaints to the Coordinating Authority in accordance 
with Article 34. 


The provider shall inform the user concerned without undue delay, either after having 
received a communication from the EU Centre indicating that it considers the report to be 
manifestly unfounded as referred to in Article 48(2), or after the expiry of a time period of 
six three months from the date of the report without having received a communication 
from the EU Centre indicating that the information is not to be provided as referred to in 
Article 48(6), point (a), whichever occurs first. The time period of six months refered to 
in this subparagraph shall be extended by up to 6 months where so requested by the 
competent authority referred to in Article 48(6)-pemta. 


Where within the three-menths- time period referred to in the second subparagraph the 
provider receives such a communication from the EU Centre indicating that the 
information is not to be provided, it shall inform the user concerned, without undue delay, 
after the expiry of the time period set out in that communication. 


The provider shall establish and operate an easy to access, accessible, effective, child- 
friendly age-apprepriate and user-friendly mechanism that allows users to notify flee to 
the provider information that indicate potential online child sexual abuse on its—the 
service. Those mechanisms shall allow for the submission of notices by individuals or 
entities exclusively by electronic means. 


The mechanisms shall be such as to facilitate the submission of sufficiently precise 
and adequately substantiated notices. To that end, the providers shall take the 
necessary measures, with particular attention to the needs of the child, to enable and 
to facilitate the submission of notices, with a view to receiving: 


(a) the reasons why the user claims that the notice contains online child sexual 
abuse; 


(b) a clear indication of the online location of the alleged online child sexual abuse 
and, where necessary, additional information specific to a service that enables 
the identification of its online location. 


The Commission, in cooperation with Coordinating Authorities and the EU Centre 
and after having conducted a public consultation, shall issue guidelines on the 
application of paragraph 3, having due regard in particular to the child's age, 
maturity, views, needs and concerns. 
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Article 13 


Specific requirements for reporting 


Providers of hosting services and providers of interpersonal communications services shall 
submit the report referred to in Article 12 using the template set out in Annex II. The 
report shall include: 


(a) 
(b) 
(ba) 


(c) 


(d) 


(e) 


(f) 


(g) 


(h) 


identification details of the provider and, where applicable, its legal representative; 
the date, time stamp and electronic signature of the provider; 


manner in which the provider became aware of the potential child sexual 
abuse’; 


allcontent data related to the reported potential online child sexual abuse; 
inchidine qnages, videos and text; 


al other available data related to the reported potential online child sexual abuse, 
including unique identifiers of the user and metadata!® related to media files 
and communications; 


whether the potential online child sexual abuse concerns the dissemination of known 
or new child sexual abuse material or the solicitation of children; 


information concerning the geographic location related to the potential online child 
sexual abuse, such as the Internet Protocol address of upload, with associated date 
and time stamp, and port number; 


information concerning the identity of any user involved in the potential online child 
sexual abuse; 


whether the provider has also reported, or will also report, the information that 
indicate potential online child sexual abuse to a third-country public authority or 
other entity competent to receive such reports ef-athird-country and if so, which 
authority or entity; 


PCY comment: the type of source of the report will be included in Annex III, Chapter I, 


point 8. 


PCY comment: the following text could be added to recital 29 in order to explain what 
metadata is: “Metadata is information about documents/files relating to their content, 
technical and physical parameters. It also includes information such as the time and 


place of their creation, information about the devices used in their creation, and about 
the modifications made to the files.” 
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la. 


(i) where the information that indicate potential online child sexual abuse concerns 
the dissemination of known or new child sexual abuse material, whether the provider 
has removed or disabled access to the material, inehidine-on-a-vehmetary basis and, 
where relevant, whether it has been done on a voluntary basis; 


(j) whether the provider considers that the report invelves-an-imminent threat to 
thelife-or-safety-ofa-child or requires urgent action; 1! 


(k) areference to this Regulation as the legal basis for reporting. 


By deviation from paragraph 1, where the information referred to in Article 12(1) 
reasonably justifies the conclusion that there is likely to be an imminent threat to the 
life or safety of a child or when the information indicates ongoing abuse, the report 
referred to in paragraph 1 of this Article shall include: 


(a) in any event, the information referred to in points (a), (b), (f), (j) and (k) of 
paragraph 1 of this Article; 


(b) the information referred to in the other points of paragraph 1 of this Article, 
only insofar as that information is immediately available and the inclusion 
thereof in the report does not delay the submission of the report. 


Where the report referred to in the first subparagaph does not contain all 
information referred to in paragraph 1 of this Article in accordance with point (b) of 
the first subparagraph, the provider of hosting services or of interpersonal 
communications services concerned shall be promptly submit an additional report 
containing all that information, updated or completed where relevant. That 
additional report shall include a reference to the initial report submitted in 
accordance with the first subparagaph and shall indicate which information has been 
updated or completed. 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to amend Annex III to improve the template where necessary in view of relevant 
technological developments or practical experiences gained. 


11 


In the template of Annex III, section 2, point 1, we could add the reason for the urgency. 
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Section 4 
Removal obligations 


Article 14 


Removal orders 


#2 ~~ Wording copied from Art. 14(5) of the TCO Regulation. 


% Wording copied from Art. 18(2) of the DSA. 
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i, 


la. 


The competent authority shall have the power to issue a removal order, in accordance 
with relevant national requirements, requiring a provider of hosting services to 
remove or disable access in all Member States of one or more specific and publicly 
available items of material disseminated tothe publHe's that, after a diligent assessment, 
the Coordinating Authority othe courts or other independent admunistrative authorities 
referred tein Article 36) is identified as constituting child sexual abuse material. 


By deviation from the first subparagraph, and without causing undue delays in the 
process of issuance of those orders, Member States may decide that such orders can 
only be issued by a judicial authority at the request of the competent authority. 
Where a Member State makes use of this possibility, it shall inform the Commission 


thereof and maintain this information updated keep-itup-te-date. The Commission 
shall make the information received publicly available and maintain this information 


updated keep it up-to-date’. 


The provider shall execute the removal order as soon as possible and in any event within 
24 + hours of receipt thereof. The provider shall take the necessary measures to ensure 
that it is capable to reinstate the material or access thereto in accordance with Article 
15(1a). 


PCY comment: this text could be included as a recital: (31a) "The rules of this Regulation 
should not be understood as affecting the relevant national requirements providing 
procedural safeguards regarding the issuing of removal, blocking or delisting orders, 


such as the control of the regularity conformity with the applicable legal requirements of 


these orders by an independent authority." 


PCY comment: the PCY wishes to discuss with delegations case examples in which a 
limitation to CSAM disseminated to the public would too narrowly define the scope of the 
removal order. 


PCY comment: This text will be accompanied by this recital: “In order to allow Member 
States to organise the process of issuance of removal, blocking or delisting orders in a manner 
compatible with their respective constitutional requirements and to enhance prior judicial 
control where deemed appropriate, they should have the possibility to require their respective 
competent authorities to request the competent judicial authority of the Member State 
concerned to issue some or all of those three types of orders under this Regulation. That 
possibility to derogate should however only concern the question which authority issues the 
orders. Accordingly, when a Member State makes use of that possibility, the competent 
authority concerned should remain responsible for assessing the need for the order at stake 
and for complying with all of the procedural requirements of this Regulation related to its 
preparation and follow-up. In that case, whilst it is for the competent judicial authority to 
conduct an additional verification of whether the conditions of this Regulation for issuing the 
order in question have been met, those conditions themselves should remain unaltered and be 
applied consistently across the Union. In the interest of effectiveness, that possibility should 
be subject to the Member State concerned taking all reasonable measures to ensure that the 
issuance of the orders by their judicial authorities does not lead to any undue delays. In 
addition, in the interest of transparency and legal certainty, it should be ensured that the 
necessary information regarding the use of the possibility is publicly available.” 


9317/23 FL/ml 26 
ANNEX JAIILIMITE JIN 


9317/23 FL/ml ZY 
ANNEX JAILILIMITE JIN 


The-competent judicial authority or the independent administrative authority shall issuea 


A removal order shall be issued using the template set out in Annex IV. Removal orders 
shall include: 


(a) 


(b) 
(c) 
(d) 


(da) 


(e) 


(f) 


(fa) 
(g) 
(h) 


(i) 


identification details of the competent—udicial_or—independent—administrative 
authority issuing the removal order and authentication of the removal order by that 
authority; 


the name of the provider and, where applicable, of its legal representative; 
the specific service in respect of fer which the removal order is issued; 


a sufficiently detailed statement of reasons explaining why the removal order is 
issued-and4n particular why the material constitutes child sexualabuse material 


where applicable, a statement of reasons explaining why the order is issued to a 
service provider that does not have its main establishment or legal 
representative in the Member State of the issuing authority according to the 
procedure provided for in Article 14a; 


an-exactuntform resource locator and where necessary _additional-clear information 
forthe identification_of enabling the provider to identify and locate the child 


sexual abuse material; 


where applicable, the information about non-disclosure during a specified time 
period, in accordance with Article 15(4), point (c); 


reporting requirements pursuant to point 7; 
a reference to this Regulation as the legal basis for the removal order; 


the date, time stamp and electronic signature of the udicial erindependent 
administrathye- competent authority issuing the removal order; 

easily understandable information about the redress available to the addressee of the 
removal order, including information about redress to a court and about the time 
periods applicable to such redress. 


The padicial autherity—ortheindependent-admunstrative authority issuing the removal 


order shall address it to the main establishment of the provider or, where applicable, to its 
legal representative designated in accordance with Article 24. 
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It-shaH-transmit The removal order shall be transmitted to the the provider’s point of 
contact referred to in Article 23(1) by electronic means capable of producing a written 
record under conditions that allow to establish the authentication of the sender, including 
the accuracy of the date and the time of sending and receipt of the order, to the 
Coordinating Authority in which the order was issued ef-establishment and to the EU 
Centre, through the system established in accordance with Article 39(2). 


It shall draft transmit the removal order in any of the official languages declared by the 
provider pursuant to Article 23(3). 


The order may also be transmitted in any of the official languages of the Member 
State issuing the order, provided that it is accompanied by a translation of at least the 
most important elements necessary for the execution of the order into any of the 
official languages declared by the provider in accordance with article 23(3). 


If the provider cannot execute the removal order on grounds of force majeure or de facto 
impossibility not attributable to it, including for objectively justifiable technical or 
operational reasons, it shall, without undue delay, inform the authority issuing the order 
efestablishment of those grounds, using the template set out in Annex V. 


The time period set out in paragraph 24 shall start to run as soon as the reasons referred to 
in the first subparagraph have ceased to exist. 


If the provider cannot execute the removal order because it contains manifest errors or 
does not contain sufficient information for its execution, it shall, without undue delay, 
request the necessary clarification te from the authority issuing the order of 
establishment, using the template set out in Annex V. 


The time period set out in paragraph 24 shall start to run as soon as the provider has 
received the necessary clarification. 


The provider shall, without undue delay and using the template set out in Annex VI, inform 
the issuing authority, Coordinating Authorisyof establishment and the EU Centre of the 
measures taken to execute the removal order, indicating, in particular, whether the provider 
removed the child sexual abuse material or disabled access thereto in all Member States 
and the date and time thereof. 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to amend Annexes IV, V and VI where necessary to improve the templates in view 
of relevant technological developments or practical experiences gained. 
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Article 14a 


Procedure Request for cross-border removal orders!’ 


Competent authorities of a Member State where the hosting service provider does not 
have its main establishment or legal representative shall have the power to request 
the issuance of a removal order to the competent authorities of the Member State 
where the hosting service provider has its main establishment or where its legal 
representative resides or is established. The communication of the request to issue the 
order shall take place via the respective Coordinating Authorities. 


Where the competent authorities of the Member State where the hosting service has 


its main establishment or where its legal representative resides or is established 
decide to issue the removal order, such an order shall be issued in accordance with 


Article 14. 


The request to issue a removal order referred to in paragraph 1 shall be transmitted 
in_any of the official languages of the Member State where the hosting service 


provider has its main establishment or where its legal representative resides or is 
established. 


PCY comment: Due to the complexity of the cross-border special procedure, the Presidency is 
seeking a possible way forward with this text proposal. 
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la. 


Article 15 


Redress and provision of information 


Providers of hosting services that have received a removal order issued in accordance with 
Article 14, as well as the users who provided the material, shall have the right to an 
effective redress. That right shall include the right to challenge such a removal order before 


the courts of the Member State of the competent—judicialautherity—or—independent 
administrathye authority that issued the removal order. 


If the order is repealed as a result of a redress procedure, the provider shall without 
undue delay reinstate the material or access thereto, without prejudice to the 
possibility to enforce its terms and conditions in accordance with Union and national 
law!8, 


When the removal order becomes final, the cempetentjudiciat-authertyor independent 
administratte authority that issued the removal order shall, without undue delay, transmit 


a copy thereof and copies of the information it has received pursuant to Article 14 (5) 
to (7) to the Coordinating Authority ef-establshment. The Coordinating Authority of 
establishment shall then, without undue delay, transmit a-cepy copies thereof to all other 
Coordinating Authorities and the EU Centre through the system established in accordance 
with Article 39(2). 


For the purpose of the first subparagraph, a removal order shall become final upon the 
expiry of the time period for appeal where no appeal has been lodged in accordance with 
national law or upon confirmation of the removal order following an appeal. 
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Wording copied from Art. 4(7) of the TCO Regulation. 
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3a. 


Where a provider removes or disables access to child sexual abuse material pursuant to a 
removal order issued in accordance with Article 14, it shall without undue delay, inform 
the user who provided the material of the following: 


(a) the fact that it removed the material or disabled access thereto; 


(b) the reasons for the removal or disabling, providing a copy of the removal order upon 
the user’s request; 


(c) the user’s right to judicial redress referred to in paragraph | and the user’s right to 
submit complaints to the Coordinating Authority in accordance with Article 34. 


The provider shall establish and operate an accessible, age-appropriate and user- 
friendly mechanism that allows users to submit to it complaints about alleged 
infringements of its obligations under this Section. It shall process such complaints in 
an objective, effective and timely manner. 

The issuing authority Coordinating Authorityof establishment may decide request, when 


removalorder—and after having consulted if necessary with relevant public authorities, 
that the provider is not to disclose any information regarding the removal of or disabling of 
access to the child sexual abuse material, where and to the extent necessary to avoid 
interfering with activities for the prevention, detection, investigation and prosecution of 
child sexual abuse or related criminal offences. 


In such a case: 


(a) the #udictal-authorityorindependent_administratt-e—authority issuing the removal 


order shall inform the provider of its decision specifying the applicable time 
period that shall be setthe+time-perted not longer than necessary and not exceeding 
twelve st-weeks, during which the provider is not to disclose such information; 


(b) the obligations set out in paragraph 3 shall not apply during that time period; 


The issuing Fhat+udicial authority or independent administrative authority may decide to 


extend the time period referred to in the second subparagraph, point (a), by a further time 
period of maximum six weeks, where and to the extent the non-disclosure continues to be 


necessary. In that case, the issuing that+udictal authority_or independent administrative 


authority shall inform the provider of its decision, specifying the applicable time period. 


lie: 
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la. 


Section 5 
Blocking obligations 


Article 16 
Blocking orders 


The competent authority Coordinating Authority of establishment shall have the power te 
request the-competent judicial _authority_of the Member State that designated it oran 
independent administrative_authority of that Member Stateto issue a blocking order, in 
accordance with relevant national requirements, requiring a provider of internet access 
services under the jurisdiction of that Member State to take reasonable measures to prevent 
users from accessing knew child sexual abuse material-+ndicated-by-allLiniferm resource 
lecators-on the list of uniform resource locators inchided in the database of indicators in 
accordance -with Article 442), point (b} and provided by the EU Centre. The competent 
authorities may make use of the list of uniform resource locators included in the 
database of indicators, in accordance with Article 44(2), point (b) and provided by the 
EU Centre. 


By deviation from the first subparagraph, and without causing undue delays in the 
process of issuance of those orders, Member States may decide that such orders can 
only be issued by a judicial authority at the request of the competent authority. 
Where a Member State makes use of this possibility, it shall inform the Commission 


thereof and_maintain this information updated keep-it up-te-date. The Commission 
shall make the information received publicly available and maintain this information 


updated keep-it-up-te-date. 


The provider shall execute the blocking order as soon as possible and in any event 
within a reasonable time period set by the issuing authority ene-week—oef_receipt 
thereef. The provider shall take the necessary measures to ensure that it is capable of 
reinstating access in accordance with Article 18(1a). 
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(b}—_requitethe—provider_to—subnut,_within—a_treasonable—time—period_set_by—that 
Coordinating Authority, the _necessary_information,_in_particular_regarding the 
accessing _or_attemptine _to—aceess—_by—users—of the-child sexual _abuse—material 


indicated by the untform resource locators, regarding the provider’s pohey to-address 
the-risk_of dissemination_of_the—child sexual abuse—_material_and tregardina the 


provider's financial and technolesical capabiities-_and size: 


(e}—_ request the EU —_Centre_te—_provide—the_necessary—information,—_in_particular 


explanations-and assurances regarding the accuracy of the _ uniform resource locators 
indicating _ child sexual abuse-material, _reaarding the quantity and nature_of that 


materiaLand regarding the -vertfications by the EU Centre and the audits referred to 
in Article 362) and Article 46) respectively: 


(d}—_ request. any_other relevant public_authority or relevant experts_or entities _to provide 


eiseene ae shall be isaued: hee it Aibcideraghat the folléeins conditions are met: 


(a) other equally effective and less intrusive measures! than blocking cannot be 
taken to prevent access to child sexual abuse material or if it is likely that such 


measure will fail; a @ die Rea Tea Dra ee 


(b) the blocking order is necessary to prevent the dissemination of the-child sexual abuse 


material te-users in the Union, having regard #-particularte the - quantity and nature 
ofthe material, to the need to protect the rights of the victims and the existence and 


19 PCY comment: examples of “less intrusive measures” can for instance be a failed notice, a 
removal order that cannot be executed or a removal order towards a so-called “bulletproof 
service provider’. 
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(d) the reasons for issuing the blocking order outweigh negative consequences for the 
rights and legitimate interests of all parties affected, having regard in particular to the 
need to ensure a fair balance between the fundamental rights of those parties, 
including the exercise of the users’ freedom of expression and information and the 
provider’s freedom to conduct a business. 


When assessing whether the conditions of the first subparagraph have been met, account 
shall be taken of all relevant facts and circumstances of the case at hand,inchidine any 
infermation-_obtained_ pursuant to_paragraph 2 and the -views-_of the providersubnitted in 
accordance with paragraph 3. 


The-Coordinating Authority_of establishment when trequestine the issuanceof blocking 


ordersandthe-cempetent judicial orindependent admunistrativeauthoritywhenissune 
the-A blocking order; shall: 


(a) ‘wherenecessary, specify effecttve and prepertionate limits and safeguards necessary 
to ensure that a blocking order is targeted and that any negative consequences 
referred to in paragraph 4, point (d), remain limited to what is strictly necessary; 


(b) subject to paragraph 6, ensure that the period of application remains limited to what 
is strictly necessary. 


The issuing Coordatine—authority shall specify in the blocking order the period during 
which it applies, indicating the start date and the end date. 


The period of application of blocking orders shall not exceed five years. 


administrative authority-iscued-at its sequel Coonudine eee or the issuing 


authority shall, where necessary and at least once every year, assess whether any 
substantial changes to the grounds for issuing the blocking orders have occurred and," 
particular, whether the conditions of paragraph 4 continue to be met. 


revacieed oF such Maier were necessary in fine light of the outcome of that assessment 
or te—take—account—ef usted +equests—or other relevant information, including 
information obtained through the reports referred to in Article +8 17(5a) and {6}, 
respecttvely an order shall be modified or repealed by the issuing authority, where 
relevant at the request of the Coordinating Authority. Fhe-previstens-ofthis Section 
shallapph te such requests sutatis mutandis. 
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Article 17 
Additional rules regarding blocking orders 


The Coordinating Authority of establishment shallissue the A blocking orders+eferredte 
in Article shall be issued using the template set out in Annex VII. Blocking orders shall 


include: 


(a) 


(b) 


(c) 
(d) 


(e) 
(ea) 
(f) 


(fa) 
(g) 
(h) 


(i) 


where applicable, the reference to the list of uniform resource locators, provided by 
the EU Centre,and the-safeguards_te—be_-previded for ineludine theimits—and 
safecuards specified _pursuant to Article 166) and -where-applicable_the reporting 
requirements set pursuant to Article 18(6); 

identification details of the cempetent—udicial _autherity—or—the—independent 
administrative authority issuing the blocking order and authentication of the blocking 
order by that authority; 


the name of the provider and, where applicable, its legal representative; 

clear information enabling the provider to identify and locate the child sexual 
abuse material:the-spectfic-service +n respect-ofwhich the detection orderis issued; 
the start date and the end date of the blocking order; 

the limits referred to in Article 16(5); 


a sufficiently detailed statement of reasons explaining why the blocking order is 
issued; 


reporting requirements pursuant to paragraph 5a; 


a reference to this Regulation as the legal basis for the blocking order; 


the date, time stamp and electronic signature of the idicial autherit—erthe 
independent administratH-e-authority issuing the blocking order; 

easily understandable information about the redress available to the addressee of the 
blocking order, including information about redress to a court and about the time 
periods applicable to such redress. 


The competentjudicial_authorityorindependent_administrattve authority issuing the 


blocking order shall address it to the main establishment of the provider or, where 
applicable, to its legal representative designated in accordance with Article 24. 


9317/23 FL/ml 36 
ANNEX JAIILIMITE JIN 


4a. 


5a. 


The blocking order shall be transmitted to the provider’s point of contact referred to in 
Article 23(1) by electronic means capable of producing a written record under 
conditions that allow to establish the authentication of the sender, including the 
accuracy of the date and the time of sending and receipt of the order, to the 
Coordinating Authority_in which the order was issued ef establishment and to the EU 
Centre, through the system established in accordance with Article 39(2). 


The blocking order shall be drafted-transmitted in any of the official languages declared 
by the provider pursuant to Article 23(3). 


If the provider cannot execute the blocking order on grounds of force majeure or de 
facto impossibility not attributable to it, including for objectively justifiable technical 
or operational reasons, it shall, without undue delay, inform the authority issuing the 
order of those grounds, using the template set out in Annex yy. 


If the provider cannot execute the blocking order because it contains manifest errors or 
does not contain sufficient information for its execution, the provider shall, without undue 
delay, request the necessary clarification te from the authority issuing the order 


Ceoordinatine Authority of establishment using the template set out in Annex VIII. 


The provider shall, without undue delay and using the template set out in Annex xx, 
inform the issuing authority of the measures taken to execute the blocking order, 
indicating, in particular, whether the provider has prevented access to child sexual 
abuse material. 


The authority issuing the order may require the provider to report to it at regular 
intervals on the measures taken and their functioning to execute a blocking order, 
including the effective and proportionate limitations and safeguards provided for. 


Upon request of the issuing authority, the provider shall also provide, without undue 
delay, such reports or any other information relating to the execution of the blocking 
order needed for the purpose of the assessment referred to in Article 16(7). 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to amend Annexes VII, yy, and VIII and xx where necessary to improve the 
templates in view of relevant technological developments or practical experiences gained. 


PCY comment: not necessary considering wording of Article 23(3). 
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la. 


Article 18 


Redress and provision of information -information-and_reportine_of blocking orders 


Providers of internet access services that have received a blocking order—as-welLas and 
users who provided er-were-prevented from _accessiie-_a specific ttem-of blocked material 
indicated_by-_the uniform resource locators in-execution_of such orders, shall have a right to 
effective redress. That right shall include the right to challenge the blocking order before 


the courts of the Member State of the cempetentjidicial _autherity—orindependent 
administrative authority that issued the blocking order. 


If the order is repealed as a result of a redress procedure, the provider shall without 
undue delay reinstate access to the material, without prejudice to the possibility to 
enforce its terms and conditions in accordance with Union and national law. 


When the blocking order becomes final, the competentjudicial authorty—or independent 
administrate authority that issued the blocking order shall, without undue delay, transmit 


a copy thereof and copies of information it has received pursuant to Article 17 (4a) to 
(5a) the Coordinating Authority of establishment. The Coordinating Authority of 
establishment shall then, without undue delay, transmit aeepy copies thereof to all other 
Coordinating Authorities and the EU Centre through the system established in accordance 
with Article 39(2). 


For the purpose of the first subparagraph, a blocking order shall become final upon the 
expiry of the time period for appeal where no appeal has been lodged in accordance with 
national law or upon confirmation of the removal order following an appeal. 


The provider shall establish and operate an accessible, age-appropriate and user-friendly 
mechanism that allows users to submit to it within-a+easenable timeframe, complaints 
about alleged infringements of its obligations under this Section. It shall process such 
complaints in an objective, effective and timely manner. 


Where a provider prevents users from accessing child sexual abuse material the uniferm 
resource teeators pursuant to a blocking order issued +7-accoerdanceswith Article 17, it shall 
take reasonable measures to inform-the those users of the following: 


(a) the fact that it does so pursuant to a blocking order; 


(c) the users? right of users who provided the blocked material to judicial redress 
referred to in paragraph 1, their rights of users to submit complaints to the provider 
through the mechanism referred to in paragraph 3 and to the Coordinating Authority 
in accordance with Article 34-as+vellasthei +ticht te-submit the requests referred to 
in paragraph 5S. 
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3. The-provider_and_the—users_teferred tein_paragraph_t shall be-entitled to request the 

Coordinating Authority that requested the issuance of the blocking order to assess whether 
users—are—wronely_prevented from accessing _acspecific_itentof material indicated by 
uniform _reseurce_tocators—pursuant tothe bleckine order—_The_provider_shall alsote 
entitled to requestunedification_or revocation-_of the blocking order_whereit considersit 
necessarydue_tosubstantial changes tothe srounds_forissume the blocking orders_that 
eccurred_after_theissuancethereof—n_particular_substantial_changes—preventine the 
providerfrom taking the required reasonable measures to-execute the blocking order, 
The Coordinating Authority shall without undue delay, diligently assess such requests and 
inform_the_provider_or the user-subnittine the request of the outcome thereof Wherett 
considers_the request tobe justified it shall request nediication_or_revecation_of the 
blocking orderin accordance with Article 164) andunformthe EU Centre. 


6. Wherethe period of appheation of the blocking order exceeds 24 months the Coordinating 


Section 5a 
Delisting obligations 


Article 18a 


Delisting orders 


1. The competent authority shall have the power to issue an order, in accordance with 
relevant national requirements, requiring a provider of online search engines under 
the jurisdiction of that Member State to take reasonable measures to delist an online 
location where child sexual abuse material can be found from appearing in search 
results. The competent authorities may make use of the list of uniform resource 
locators included in the database of indicators, in accordance with Article 44(2), point 
(b) and provided by the EU Centre. 


la. By deviation from the first subparagraph, and without causing undue delays in the 
process of issuance of those orders, Member States may decide that such orders can 
only be issued by a judicial authority at the request of the competent authority. 
Where a Member State makes use of this possibility, it shall inform the Commission 
thereof and maintain this information updated keep-it wp-te-date. The Commission 
shall make the information received publicly available and maintain this information 
updated keep-it up-te-date. 
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The provider shall execute the delisting order without undue delay and in any event 
within a reasonable time period set by the issuing authority-one-weel_of receipt-of the 
erder. The provider shall take the necessary measures to ensure that it is capable of 
reinstating the delisted online location to appear in search results in accordance with 
Article 18c(2). 


A delisting order shall be issued where the following conditions are met: 


(a) the delisting is necessary to prevent the dissemination of the child sexual abuse 
material in the Union, having regard in particular to the need to protect the 
rights of the victims; 


(b) search results correspond, in a sufficiently reliable manner, to online locations 
where child sexual abuse material can be found. 


The issuing authority shall specify in the delisting order the period during which it 
applies, indicating the start date and the end date. 


The period of application of delisting orders shall not exceed five years. 


The Coordinating Authority or the issuing authority shall, where necessary and at 
least once every year, assess whether any substantial changes to the grounds for 
issuing the delisting orders have occurred and whether the conditions of paragraph 4 
continue to be met. 


Where necessary in the light of the outcome of that assessment or information of the 
reports referred to in Article 18b(6) an order may be modified or repealed by the 
issuing authority, where relevant at the request of the Coordinating Authority. 


Article 18b 
Additional rules regarding delisting orders 


A delisting order shall be issued using the template set out in annex zz. Delisting 
orders shall include: 


(a) identification details of the authority issuing the delisting order and 
authentication of the order by that authority; 


(b) the name of the provider and, where applicable, its legal representative; 


(c) clear information enabling the provider to identify and locate the child sexual 
abuse material; 
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(d) the start and end date of the delisting; 


(e) a sufficiently detailed statement of reasons explaining why the delisting order is 
issued; 


(f) reporting requirements pursuant to point 6; 
(g) areference to this Regulation as the legal basis for delisting; 


(h) the date, time stamp and electronic signature of the authority issuing the 
delisting order; 


(i) easily understandable information about the redress available, including 
information about redress to a court and about the time periods applicable to 
such redress. 


2. The authority issuing the delisting order shall address it to the main establishment of 
the provider or, where applicable, to its legal representative designated in accordance 
with Article 24. 


The delisting order shall be transmitted to the provider’s point of contact referred to 
in Article 23(1) by electronic means capable of producing a written record under 
conditions that allow to establish the authentication of the sender, including the 
accuracy of the date and the time of sending and receipt of the order to the 
Coordinating Authority in which the order was issued ef establishment and to the EU 
Centre, through the system established in accordance with Article 39(2). 


3. The delisting order shall be transmitted in any of the offical languages declared by 
the provider pursuant to Article 23(3). 


4. If the provider cannot execute the delisting order on grounds of force majeure or de 
facto impossibility not attributable to it, including for objectively justifiable technical 
or operational reasons, it shall, without undue delay, inform the authority issuing the 
order of those grounds, using the template set out in Annex qq. 


21 | PCY comment: not necessary considering wording of Article 23(3). 
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If the provider cannot execute the delisting order because it contains manifest errors 
or does not contain sufficient information for its execution, the provider shall, without 
undue delay, request the necessary clarification from the authority issuing the order, 
using the template set out in Annex pp. 


The provider shall, without undue delay and using the template set out in Annex ww, 
inform the issuing authority of the measures taken to execute the delisting order, 
indicating, in particular, whether the provider has prevented search results for the 
online location with child sexual abuse material to appear. 


The authority issuing the order may require the provider to report to it regularly on 
the measures taken to execute a delisting order. 


The Commission shall be empowered to adopt delegated acts in accordance with 
Article 86 in order to amend Annexes zz, qq and pp where necessary to improve the 
templates in view of relevant technological developments or practical experiences 
gained. 


Article 18c 
Redress and provision of information- 


Providers of online search engines that have received a delisting order and users that 
provided the material to a delisted online location shall have a right to effective 
redress. That right shall include the right to challenge the delisting order before the 
courts of the Member State of the authority that issued the delisting order. 


If the order is repealed as a result of a redress procedure, the provider shall without 
undue delay reinstate the delisted online location to appear in search results, without 
prejudice to the possibility to enforce its terms and conditions in accordance with 
Union and national law. 


When the delisting order becomes final, the issuing authority shall, without undue 
delay, transmit a copy thereof and information it has received pursuant to Article 18b 
(4) to (6) to the Coordinating Authority of establishment. The Coordinating Authority 
of establishment shall then, without undue delay, transmit a copies thereof to all other 
Coordinating Authorities and the EU Centre through the system established in 
accordance with Article 39(2). 


For the purpose of the first subparagraph, a delisting order shall become final upon 
the expiry of the time period for appeal where no appeal has been lodged in 
accordance with national law or upon confirmation of the delisting order following an 
appeal. 
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3a. The provider shall establish and operate an accessible, age-appropriate and user- 
friendly mechanism that allows users to submit to it complaints about alleged 
infringements of its obligations under this Section. It shall process such complaints in 
an objective, effective and timely manner. 


4. Where a provider prevents users from obtaining search results for child sexual abuse 
material corresponding to an online location pursuant to a delisting order, it shall 
take reasonable measures to inform users that provided the material to a delisted 
online location and those users of the following: 


(a) the fact that it does so pursuant to a delisting order; 


(b) the right of users that provided the material to a delisted online location to 
judicial redress referred to in paragraph 1 and users’ right to submit complaints 
to the Coordinating Authority in accordance with Article 34. 


Section 6 
Additional provisions 


Article 19 
Liability of providers 


Providers of relevant information society services shall not be liable for child sexual abuse offences 
if solehbecause they carry out, in good faith, the-mecessary activities to comply with the 
requirements—of this Regulation, in particular activities aimed at assessing and mitigating risk, 
detecting, identifying, reporting, removing, disabling efaccess to, blocking or delisting from 


search results reporting online child sexual abuse #+-accordance-with these requirements. 
Article 20 


Victims’ right to information 


Le Persons residing in the Union shall have the right to receive, upon their request, from the 
Coordinating Authority designated-by in the Member State where they reside, information 
regarding any instances where the dissemination of known child sexual abuse material 
depicting them is reported to the EU Centre pursuant to Article 12. Persons with 
disabilities shall have the right to ask and receive such an information in a manner 
accessible to them. 


That Coordinating Authority shall transmit the request to the EU Centre through the system 
established in accordance with Article 39(2) and shall communicate the results received 
from the EU Centre to the person making the request. 
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The request referred to in paragraph 1 shall indicate: 
(a) the relevant item or items of known child sexual abuse material; 


(b) where applicable, the individual or entity that is to receive the information on behalf 
of the person making the request; 


(c) sufficient elements to demonstrate the identity of the person making the request. 
The information referred to in paragraph | shall include: 

(a) the identification of the provider that submitted the report; 

(b) _ the date of the report; 


(c) whether the EU Centre forwarded the report in accordance with Article 48(3) and, if 
so, to which authorities; 


(d) whether the provider reported having removed or disabled access to the material, in 
accordance with Article 13(1), point (1). 


Article 21 
Victims’ right of assistance and support for removal 


Providers of hosting services shall provide reasenable-assistance, on request, to persons 
residing in the Union that seek to have one or more specific items of known child sexual 
abuse material depicting them removed or to have access thereto disabled by the provider. 


Persons residing in the Union shall have the right to receive support;upernthet+request, 
from the Coordinating Authority designated-by in the Member State where they-persen 
resides, to request assistance,-suppert from the EU Centre when they seek to have a 
provider of hosting services remove or disable access to one or more specific items of 
known child sexual abuse material depicting them. Persons with disabilities shall have the 
right to ask and receive any information relating to such support in a manner accessible to 
them. 


That Coordinating Authority shall transmit the request to the EU Centre through the system 
established in accordance with Article 39(2) and shall communicate the results received 
from the EU Centre to the person making the request. 
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The requests referred to in paragraphs | and 2 shall indicate the relevant item or items of 
child sexual abuse material. 


The EU Centre’s support referred to in paragraph 2 shall include, as applicable: 


(a}—_-suppertin connection te requesting the provider’s assistance referred to in_paragraph 
az 


(b) verifying whether the provider removed or disabled access to that item or those 
items, including by conducting the searches referred to in Article 49(1); 


(c) notifying the item or items of known child sexual abuse material depicting the person 
to the provider and requesting removal or disabling of access, in accordance with 
Article 49(2); 


(d) where necessary, informing the Coordinating Authority of establishment of the 
presence of that item or those items on the service, with a view to the issuance of a 
removal order pursuant to Article 14. 
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Article 2222 23 
Preservation of information 


Providers of hosting services and providers of interpersonal communications services shall 
preserve the neeessary content data and other data processed that is necessary for taking 
in-connectionte the measures taken to comply with this Regulation and the personal data 
generated through such processing, when the following measures have been taken or for 
the purposes of complaints or redress procedures ecemplaints-on}yfer-one_or-meoreofthe 


fellowine-purpeses, as applicable: 


(xa) insofar as strictly necessary for using the technologies referred to in Article 10, 
involving in particular the automatic, intermediate and temporary preservation 
of such data for the use of the indicators provided by the EU Centre, as well as 
for applying the safeguards referred to in Article 10, when executing a detection 
order issued pursuant to Article 7; 


22 


23 


PCY comment: recital 39 could be amended as follows: (39) To avoid disproportionate 
interferences with users’ rights to private and family life and to protection of personal data, 
the data related to instances of potential online child sexual abuse should not be preserved by 
providers of relevant information society services, unless and for no longer than necessary for 
one or more of the purposes specified in this Regulation and subject to an appropriate 
maximum duration. In that regard, the requirements to preserve such data in connection 
to the execution of detection orders should not be understood as allowing or requiring 
the preservation of all users’ data processed for such detection purposes in general. They 
should rather be understood as requiring only the preservation of content data and 
other data processed insofar as this is strictly necessary to use the relevant technologies 
meeting the requirements of this Regulation, covering in particular caching-like 
activities involving the automatic and intermediate preservation for purely technical 
reasons and for very short periods of time needed to use the relevant indicators to detect 
possible child sexual abuse online, as well as to apply the safeguards required under this 
Regulation in connection to the use of those technologies, covering in particular the 
application of measures to prevent, detect and remedy misuse, to ensure regular human 
oversight and to carry out regular reviews, As those preservation requirements relate only 
to this Regulation, they should not be understood as affecting the possibility to store relevant 
content data and traffic data in accordance with Directive 2002/58/EC or the application of 
any legal obligation to preserve data that applies to providers under other acts of Union law or 
under national law that is in accordance with Union law.” 


PCY comment: once more clarity is achieved on the detection order, the PCY is of the view 
that this article must be discussed in terms of its scope in order to minimise legal risks, in 
particular in view of the fact that this article covers content data in interpersonal 
communications. 
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la. 


(a) executing a-detection-_order issued pursuant toArticle-7or a removal order issued 


pursuant to Article 14 fer-ableckinge-erderpursuant teArticle 16 ora—delisting 
order pissin to etdete teat, 


(b) reporting information that indicate potential online child sexual abuse to the EU 
Centre pursuant to Article 12; 


(c) blocking the account of, or suspending or terminating the provision of the service to, 
the user concerned; 


(d) handling users’ complaints to the provider or to the Coordinating Authority, or the 
exercise of users’ right to administrative or judicial redress, in respect of alleged 
infringements of this Regulation. 


(e}— 

Upon a request respending—te—requests issued by a competent law—enforcement 
authorityies and judicial _autherities_[in accordance with the applicable law], providers 
shall with-a-iew-te provideing them requesting authority with the necessary information 
for the prevention, detection, investigation or prosecution of child sexual abuse offences; 
or the handling of complaints or admininstrative or judicial redress proceedings, 
insofar as the content data and other data have been preserved for one of the purposes in 
paragraphs 1(a) to (d). relate te-a report that the provider has submited te the EU Centre 
pursuantte Article 12, 

As regards the first subparagraph, point (a), the provider may also preserve the information 
for the purpose of improving the effectiveness and accuracy of the technologies to detect 
online child sexual abuse for the execution of a detection order issued to it in accordance 
with Article 7. However, it shall not store any personal data for that purpose. 


Providers shall preserve the information referred to in paragraph 1 for no longer than 
necessary for the applicable purpose and, in any event, no longer than 12 months from the 
date of the measures taken that led to the obligation to preserve the content data and 
other data processed. : A He 
first. 


Providers Fkey—shall, upon request from the competent natiernalauthority —erceourt, 
preserve the information for a further specified period, set by thatthe requesting authority 
erceurt-where and to the extent necessary for ongoing administrative or judicial redress 
proceedings, as referred to in paragraph 1, point (d). 
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Providers shall ensure that the information referred to in paragraph 1 is preserved in a 
secure manner and that the preservation is subject to appropriate technical and 
organisational safeguards. Those safeguards shall ensure, in particular, that the information 
can be accessed and processed only for the purpose for which it is preserved, that a high 
level of security is achieved and that the information is deleted upon the expiry of the 
applicable time periods for preservation. Providers shall regularly review those safeguards 
and adjust them where necessary. 


Article 23 
Points of contact 


Providers of relevant information society services shall establish a single point of contact 
allowing for direct communication, by electronic means, with the Coordinating 
Authorities, other competent authorities of the Member States, the Commission and the EU 
Centre, for the application of this Regulation. 


The providers shall communicate to the EU Centre and make public the information 
necessary to easily identify and communicate with their single points of contact, including 
their names, addresses, the electronic mail addresses and telephone numbers. 


The providers shall specify in the information referred to in paragraph 2 the official 
language or languages of the Union, which can be used to communicate with their points 
of contact. 


The specified languages shall include at least one of the official languages of the Member 
State in which the provider has its main establishment or, where applicable, where its legal 
representative resides or is established. 
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Article 24 
Legal representative 


Providers of relevant information society services which do not have their main 
establishment in the Union shall designate, in writing, a natural or legal person as its legal 
representative in the Union for the purposes of this Regulation. 


The legal representative shall reside or be established in one of the Member States where 
the provider offers its services. 


The provider shall mandate its legal representatives to be addressed in addition to or 
instead of the provider by the Coordinating Authorities, other competent authorities of the 
Member States and the Commission on all issues necessary for the receipt of, compliance 
with and enforcement of orders and decisions issued in relation to this Regulation, 
including detection orders, removal orders and, blocking orders and delisting orders. 


The provider shall provide its legal representative with the necessary powers and resources 
to cooperate with the Coordinating Authorities, other competent authorities of the Member 
States and the Commission and to comply with the orders and decisions referred to in 
paragraph 3. 


The designated_legal representative may be held liable for non-compliance with obligations 
of the provider under this Regulation, without prejudice to the liability and legal actions 
that could be initiated against the provider. 


The provider shall notify the name, address, the electronic mail address and telephone 
number of its legal representative designated pursuant to paragraph 1| to the Coordinating 
Authority in the Member State where that legal representative resides or is established, and 
to the EU Centre. The provider or the legal representative Fhey-shall ensure that that 
information is up to date and publicly available. 


The designation of a legal representative within the Union pursuant to paragraph | shall 
not amount to an establishment in the Union. 
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CHAPTER III 


SUPERVISION, ENFORCEMENT AND COOPERATION 


Section 1 
Coordinating Authorities of the Member States-forchid sexualabuseissues*+ 


Article 2525 


Coordinating Authorities forehild_-sexualabuseissues and other competent authorities 


Member States shall, by (Pate— Ave-eighteen months from the date of entry into force of 
this Regulation}, designate one or more competent authorities as responsible for the 


application, and supervision and enforcement of this Regulation Ceempetentautherities’} 


Where a Member State designates more than one competent authority, it shall 
appoint one of those competent authorities as Coordinating Authority. Where it 
designates only one competent authority, that competent authority shall be the 
Coordinating Authority. 


25 


PCY comment: see in annex a list of the tasks of the Coordinated Authorities. 


PCY comment: the new logic could be explained in a recital, as follows: 


“With a view to leaving Member States a degree of flexibility so as to implement solutions 
best adapted to their particular circumstances, whilst also ensuring the coordination at 
domestic level and cooperation at EU level needed to ensure the consistent, efficient and 
effective application of this Regulation, Member States should be able to designate several 
competent authorities yet be required in that case to appoint one of them as the Coordinating 
for which certain tasks are exclusively reserved under this Regulation. Therefore, each 
mention of competent authorities in this Regulation should be interpreted as referring to the 
relevant competent authorities designated by the Member States, including where relevant 
Coordinating Authorities, while each mention of Coordinating Authorities should be 
interpreted as referring to Coordinating Authorities only, to the exclusion of any other 
competent authorities that the Member States may have designated. Member States should 
also be able to provide for the ex post administrative or judicial review centre} of 
the orders issued by competent authorities, in accordance with national law, 
including when such eentrel review is not specifically provided for in this 
Regulation.” 
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The Coordinating Authority shall in any event be responsible for ensuring coordination at 

national level in respect of these all matters relating to the application, supervision and 

enforcement of this Regulation and—fer—centributine to—the—effective—efficient and 
consistent apphcation, and enforcement of this Resulation throuchout the Union. 


Where a Member State designates more than one competent authority #1-additiontethe 
Coordinating Authority, it shall ensure that the respective tasks of those authorities and-ef 
the-Coordinatine Authority including those of the Coordinating Authority, are clearly 
defined and that they cooperate closely and effectively when performing their tasks. Fhe 
Member State concerned shall conmmunicate the name of the other competent authorities_as 
wellas_thet respective tasks to the EU Centre and the Commission. 


Within one week after the designation of the competent authorities, including the 
Coordinating Authorities and-ether-competent authorities pursuantte-paragrapht, Member 
States shall make publicly available, and communicate to the Commission and the EU 
Centre, the names of their—CoordmatineAuthority_and_other—compentent those 
authorities as well as their respective tasks or sectors. They shall keep that information 
updated. 


Each-Member States shall ensurethatacontact pointis_desienated-or establish a contact 


point within its the-Coordinating Authority’s office to handle requests for clarification, 
feedback and other communications in relation to all matters related to the application and 
enforcement of this Regulation+a—that Member—State. Member States shall make the 
information on the contact point publicly available and communicate it to the EU Centre. 
They shall keep that information updated. 


Within two weeks after the designation of the Coordinating Authorities pursuant to 
paragraph 2, the EU Centre shall set up an online register listing the Coordinating 
Authorities and their contact points. The EU Centre shall regularly publish any 
modification thereto. 


Competent authorities Coordinatize—Authorities may, where necessary for the 


performance of their tasks under this Regulation, request through the Coordinating 
Authority, the assistance of the EU Centre in carrying out those tasks, in particular, by 
requesting the EU Centre to: 


(a) provide certain information or technical expertise on matters covered by this 
Regulation; 


(b) assist in assessing, in accordance with Article 5(2), the risk assessment conducted or 
updated or the mitigation measures taken by a provider of hosting or interpersonal 
communication services under the jurisdiction of the Member State that designated 


the requesting competent authority Coordimatine Authority; 
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(c) provide opinion on yvertfy the possible need for a competent authority to request 
competent national authorities toissue the issuance of a detection order,-aremeval 
order, ora bleckine orderin respect of a service under the jurisdiction of the Member 


State that designated that Coordinatine Authority; 

[(d) provide opinion on vertfy the effectiveness of a detection order or-a+remevalerder 
issued upon the request of the requesting Coordinating Authoritys. ]26 

The EU Centre shall previde such assistance free of charge and in accordance with Hts tasks 


and obligations_underthis Reeulation-and insefar as its resources-_and priorities allow. 27 


The requirements_apphcable to Coordinating Authorities set out in Articles 26,27 28, 29 
and 30 -shall_alse—apphte—any—other_competent_authorities that the-_Member States 
designate pursuantte paragraph t 
Article 26 
Requirements for Coordinating competent Authorities 


Member States shall ensure that the competent authorities Coordinating Authorities that 
they have designated carry out perferm their tasks under this Regulation in an objective; 
taparttal transparent and timely and non-discriminatory manner, while fully respecting 
the fundamental rights ef al-parties—affected2®. Member States shall ensure that their 
Coordinating Authorities those authorities have adequate technical, financial and human 
resources to carry out their tasks. 


26 


27 


28 


29 


PCY comment: to be revised pending further discussions on detection orders. 
PCY comment: moved to Art 43(5)(b) on the EU Centre. 


PCY comment: this recital (copied from recital 35 TCO, except for the marked changes) 
could be included: “For the purposes of this Regulation, Member States should designate 
competent authorities. This should not necessarily imply the establishment of a new authority 
and it should be possible to entrust an existing body with the functions provided for in this 
Regulation. This Regulation should require the designation of authorities competent for 
issuing removal orders, scrutinising removal orders, overseeing specific measures and 
imposing penalties, while it should be possible for each Member State to decide on the 
number of competent authorities to be designated and whether they are administrative or law 
enforcement or judicial other than courts. Member States should ensure that the competent 
authorities fulfil their tasks in an objective and non-discriminatory manner and do not seek or 
take instructions from any other body in relation to the exercise of the tasks under this 
Regulation. This should not prevent supervision in accordance with national constitutional 
law. Member States should communicate the competent authorities designated under this 
Regulation to the Commission, which should publish online a register listing the competent 
authorities. That online register should be easily accessible to facilitate the swift verification 
of the authenticity of removal orders by the hosting service providers.” 


PCY comment: wording copied from Art. 13(2) of the TCO Regulation. 
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Those authorities Fhe-Coordinating Authorities shall not seek or take instructions 


from any other body in relation to carrying out their tasks under this Regulation°°. 


23. 


3 4. 


When ered ot the hist tae eee he pees Hecate aH tbs 


Regulation, the-Coordinatine Authorities shal act -with_complete independence—tothat 
aim,Member States shall ensure in particular that they: 


(a}—aretegally and functionalhndependent from any other public authority; 
(b} have a status enabling thento-act objectivelh and impartially when carrying outtheir 
(c}— are free from-any externalinfluence whether direct or indirect: 


(d) neither seek nor take instructions from any other public authority or any private 


Paragraph 2-1 shall not prevent supervision of the Ceerdinatine competent aAuthorities in 
accordance with national eenstitutieral lawtethe-extent that such-supervision_dees-not 
Hecht tidepcidctecis- recipe ace hs ena, 

The Cocerdinatine Autherties_and ether competent authorities shall ensure that their 
relevant-members—of staff have the required qualifications, experience, integrity and 


technical skills to perferm carry out the application, supervision and enforcement 
under this Regulation duties. 


30 


PCY comment: 1) This text could be included as a recital: “Member States should be free to 
designate any national authority fulfilling the requirements of this Regulation as 
competent authority for the purpose of this Regulation. However, since the tasks of 
competent authorities under this Regulation are administrative in nature, they are 
subject to control by courts. Moreover, this Regulation requires certain orders to be 
issued by courts as an additional safeguard. Therefore, for reasons of legal clarity and 
by virtue of the specific role performed by courts in comparison with other 
administrative and judicial authorities, courts should not be designated as competent 
authorities. Nothing in Article 26 should be interpreted as meaning that Member States 
are required to apply differentiated independence requirement to, respectively, courts 
and other judicial authorities such as public prosecutors.” 


2) To address some delegations’ concerns that competent authorities would be getting 
“instructions” from judicial authorities, a recital could be added, as follows: “In order to 
ensure that the competent authorities designated under this Regulation carry out their tasks 
under this Regulation in an objective, adequate and responsible manner, in compliance with 
the fundamental rights guaranteed under the Charter and without any undue interference, 
certain requirements in this respect should be provided for. Those requirements should not be 
interpreted as precluding judicial review of the activities of competent authorities in 
accordance with EU law or with national law in accordance with EU law.” 
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The management and other staff of the Coordinating Authorities shall, in accordance with 
Union or national law, be subject to a duty of professional secrecy both during and after 
their term of office, with regard to any confidential information which has come to their 
knowledge in the course of the performance of their tasks. Member States shall ensure that 
the management and other staff are subject to rules guaranteeing that they can carry out 
their tasks in an objective, impartial and independent manner, in particular as regards their 
appointment, dismissal, remuneration and career prospects. 


Section 2 
Powers of competent authorities the Coordinating Authorities of Member States 
Article 2731 


Investigatory and enforcement powers 


Where needed in order to fer-carrying out their tasks under this Regulation, competent 
authorities CoordimatineAuthorities er—other—competent—autherities shall have the 
following powers of investigation, in respect of conduct by providers of relevant 
information society services falling within the competence underthe jurisdiction of the 
their Member State that desienated them: 


(a) the power to require those providers, as well as any other persons acting for purposes 
related to their trade, business, craft or profession that may reasonably be aware of 
information relating to a suspected infringement of this Regulation, to provide such 


information without undue delay-within-a+easenable tme period; 


(b) the power to carry out, or to request a judicial authority to order, on-site 
inspections of any premises that those providers or the-other-those persons referred 
to-in- peut{a) use for purposes related to their trade, business, craft or profession, or 
to request other public authorities to do so, in order to examine, seize, take or obtain 
copies of information relating to a suspected infringement ef this Resulatien in any 
form, irrespective of the storage medium; 


PCY comment: copied word for word from Art. 51 of the DSA as a baseline for further 
discussions. Differences include that (1) both the Coordinating and competent authorities are 
included; (11) this text speaks about “user”, not “the recipient of a service” and (ii1) in point 3b 
below the wording “or the infringement results in the regular and structural facilitation of 
child sexual abuse offences” has been maintained. The restruturing of Articles 27 to 30 to 
ensure alignement with DSA has lead to the fact that some cross-references need to be 
corrected. This will be done once the text is stable. For the delegations’ ease, a clean 
version of Articles 27-30 is in annex. The PCY is of the view that this section must be 


explained by recitals such as the ones in the DSA Regulation (114-116). 
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(c) 


(d) 


the power to ask any member of staff or representative of those providers or the ether 
those persons to give explanations in respect of any information relating to a 


suspected infringement ef this-Regulation—and to record the answers by any 
technical means; 


the power to request information, including to assess whether the measures taken to 
execute a detection order, removal order,—er blocking order or delisting order 
comply with the requirements of this Regulation. 


2 Member States may erant additional investigative powers_to the Coordinating Authorities. 


Article 28 
EPO FC eHLCHEpOWers 


2.+—-Where needed for carrying out their tasks under this Regulation, competent authorities 


Coordinating Authorities shall have the following enforcement powers, in respect of 
providers of relevant information society services falling within the competence under 


the urisdiction of the their Member State thatdestenated them: 


(a) 


(b) 


(d) 


(e) 


the power to accept the commitments offered by those providers in relation to their 
compliance with this Regulation and to make those commitments binding; 


the power to order the cessation of infringements ef this-Resulation and, where 
appropriate, to impose remedies proportionate to the infringement and necessary to 
bring the infringement effectively to an end or to request a judicial authority in 
their Member States to do so; 


the power to impose fines, or request a judicial authority in their Member State to do 
so, in accordance with Article 35 for failure to comply with infringements-of this 
Regulation, including nern-comphance-with any of the investigative orders issued 


pursuant to paragraph 1 of this Article 2+end+e-peint{(b} ofthis paragraph; 


the power to impose a periodic penalty payment, or to request a judicial authority 
to do so, in accordance with Article 35 to ensure that an infringement ef+this 
Regulation is terminated in compliance with an order issued pursuant to point (b) of 
this subparagraph or for failure to comply with any of the orders issued pursuant to 


paragraph | of this Article. 2+ and+te-pemt(b} ofthis paragraph; 


the power to adopt interim measures or to request the competent national judicial 
authority to do so, to avoid the risk of serious harm. 
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2 Member States may erant additional enforcement powers_to the Coordinating Authorities. 

3. As regards the first subparagraph 4, points (c) and (d), competent authorities 
Coordinating Authorities shall also have the enforcement powers set out in those points 
alse-in respect of the other persons referred to in paragraph 1-A+rticle 27, for failure to 
comply with any of the orders issued to them pursuant to that paragraph Article. 4. They 
shall only exercise those enforcement powers after having provided those other persons in 
good time with all relevant information relating to such orders, including the applicable 
time-period, the fines or periodic payments that may be imposed for failure to comply and 
redress-the possibilities for redress. 


Article 29 
\dditional enti 


3.4—Where needed for carrying out their tasks under this Regulation, competent authorities 


Coordinating Authorities shall havethe—additional enforcement _powers—referred ton 


paragraph, in respect of providers of relevant information society services falling within 


the competence underthe jurisdiction of their Member State, where thatdesienated them, 

(a}—all other powers pursuant to this Articles27+and2#o bring about the cessation of an 
infringement efthisReesutation have been exhausteds 

(b)}—and the infringement has not been remedied or is continuing and is -persists; 


(e} the infringement ecauses-causing serious harm which cannot be avoided through the 
exercise of other powers available under Union or national law, also have the power 
to take the following measures: 


(a) to require the management body of the providers, without undue delay, to examine 


the situation, within-areasenable time period and te: 


4)—-adopt and submit an action plan setting out the necessary measures to terminate 
the infringement; 


44— ensure that the provider takes those measures; and 


44)— report on the measures taken; 
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(b) where the competent authorities consider that a provider of relevant 
information society services has not sufficiently complied with the requirements 
of point (a), that the infringement has not been remedied or is continuing and is 
causing serious harm, and that that infringement entails a criminal offence 
involving a threat to the life or safety of persons or the infringement results in 
the regular and structural facilitation of child sexual abuse offences, to request 
that the competent judicial authority or other independent administrative authority 
of its the Member State that designated the-Coordinatine Authority to order the 
temporary restriction of access of users of the service concerned by the infringement 
or, only where that is not technically feasible, to the online interface of the provider 


on which the infringement takes place. -wherethe-Ceordinatine Authority considers 
that: 


4) the provider has not sufficiently comphedavith the requirementsof pomt(a): 
he inte cous] : 


ii) the inf lis in d | facilitati C child 
abuse-offences. 


3.—The Coordinating Authority competent authorities shall, prior to submitting the request 
referred to in this paragraph 2, point (b), invite interested parties to submit written 
observations within a period that shall not be less than two weeks, describing the 
measures that it intends to request and identifying the intended addressee or 
addressees thereof. The provider, the intended addressee or addressees and any other 
third party demonstrating a legitimate interest shall be entitled to participate in the 
proceedings before the competent judicial authority or other independent 
administrative authority. 
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4.———_Any measure ordered upentherequest referred tein paragraph 2,_peimt (b), shall be 
proportionate to the nature, gravity, recurrence and duration of the infringement, without 
unduly restricting access to lawful information by users of the service concerned. 


The temporarytrestriction of access shall be apphfor a period of four weeks, subject to the 
possibility for the competent judicial authority or other independent administrative 
authority of the Member State, in its order, to allow the Coordinating Authority er ether 
competent authorities_inchidine the-Coordinatine Authorities, to extend that period 
for further periods of the same lengths, subject to a maximum number of extensions set by 
a that judicial authority or other independent administrative authority. 


The Coordinatinge—Authertty competent authorities, inehidine—the—Coordinatine 
Authorities, referred to in the previous subparagraph shall only extend the period 


where-#-considers, having regard to the rights and legitunate-interests of all parties affected 
by the that restriction and all relevant faets-and circumstances, including any information 
that the provider, the addressee or addressees and any other third party that demonstrated a 
legitimate interest may provide to it, it considers that both of the following conditions 
have been met: 


(a) the provider has failed to take the necessary measures to terminate the infringement; 


(b) the temporary restriction does not unduly restrict access to lawful information by 
users of the service, having regard to the number of users affected and whether any 
adequate and readily accessible alternatives exist. 


Where the Coordinating Authority competent authorityinehidine the-Cooerdinatine 
Authority, considers that the conditions set out in the fourth subparagraph, points (a) 


and (b) these-tve—conditiens have been met but it cannot further extend the period 
pursuant to the fourth secead- subparagraph, it shall submit a new request to the competent 
judicial authority or other independent administrative authority, as referred to in the 
first subparagraph, point (b). 
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4. 1—The measures taken by the Coordinating Authorities competent authorities in the exercise 
of their nvestigatery_and enforcement powers listed in paragraphs 1, 2 and 3 referredte 
in- Articles 27, 28-and 29 shall be effective, dissuasive and proportionate, having regard, in 
particular, to the nature, gravity, recurrence and duration of the infringement ofthis 
Regulation—or suspected infringement to which those measures relate, as well as the 
economic, technical and operational capacity of the provider of relevant information 
society services concerned, where relevant-appHeable. 


5.2,——Member States shall lay down specific rules and procedures for the exercise of the 
powers pursuant to paragraphs 1, 2 and 3 and shall ensure that any exercise of those 
the investigatery_and enforcement powers referred to4n Articles 27, 28 and 201s subject to 
adequate safeguards laid down in the applicable national law in compliance with the 
Charter and with the general principles of Union law te-+espect the fondamental schts 
ef al parties-affeeted. In particular, those measures shall only be taken in accordance with 
the right to respect for private life and the rights of defence, including the rights to be 
heard and of access to the file, and subject to the right to an effective judicial remedy of all 
parties affected parties. 


Article 31 
Searches to verify compliance 


The competent authorities Coordinating Authorities shall have the power to carry out searches on 
publicly accessible material on hosting services to detect the dissemination of known or new child 
sexual abuse material, using the indicators contained in the databases referred to in Article 44(1), 
points (a) and (b), where necessary to verify whether the providers of hosting services under the 
jurisdiction of the Member State that designated the Coordinating Authorities comply with their 
obligations under this Regulation. 
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Article 32 
Notificati C] hild Lal ‘al 
Coordinating A uthorties_shall have the _powerto notify providers_of hestine _servicesanderthe 
purisdiction_of the Member State that designated them of the presence_on then service_of one—or 
more-specificitems_of known child sexual abuse material and to request them te remove_or disable 
aceess_tothat itemor these items, for the providers’ voluntary consideration. 


The-+request shall clearly set cut the identification detals of the Coordinating Authority making the 


request and information_onits-contact point referred toin Article 256), the necessary information 
for the identification of the item or items of known child sexual abuse material concerned as well 


as_the_reasons_for_the requestThe request shall also clearly state that it is_forthe_provider’s 
volintary-_consideration 3? 


Section 3 
Other provisions on enforcement 
Article 33 
Jurisdiction 


1. The Member State in which the main establishment of the provider of relevant information 
society services is located shall have jurisdiction for the purposes of this Regulation. 


2. A provider of relevant information society services which does not have an establishment 
in the Union shall be deemed to be under the jurisdiction of the Member State where its 
legal representative resides or is established. 


Where a provider failed to appoint a legal representative in accordance with Article 24, all 
Member States shall have jurisdiction. Where a Member State decides to exercise 
jurisdiction under this subparagraph, it shall inform all other Member States and ensure 
that the principle of ne bis in idem is respected. 


32, PCY comment: It is the view of the PCY that this power can be explained and described in a 
recital that builds on recital 40 of the TCO Regulation and Article 16 DSA. The recital below 
clarifies that competent authorities can make use of notice and action mechanisms and be 
appointed as trusted flaggers: “Nothing in this Regulation precludes competent authorities 
designated therein to submit notices to providers of hosting services on the basis of 
notice and action mechanisms pursuant to Article 16 of Regulation (EU) 2022/2065 
(Digital Services Act) to notify them of the presence of one or more specific items of 
known child sexual abuse material, nor to request the status of trusted flagger under the 
conditions established under Article 22 of that Regulation. ” 


9317/23 FL/ml 60 
ANNEX JAILILIMITE JIN 


Article 3433 
Right ofusers-of the service to lodge a complaint 


Users and any body, organisation or association mandated to exercise the rights 
conferred by this Regulation on their behalf shall have the right to lodge a complaint 
against providers of relevant information society services alleging an infringement of 
this Regulation affecting them against providers_of relevant information _society_services 
with the Coordinating Authority designatedby in the Member State where the user is 
located resides-or is-established. 


Coordinating Authorities shall provide child-friendly mechanisms to submit a complaint 
under this Article and adopt a child-sensitive approach when handling complaints 
submitted by children, taking due account of the child's age, maturity, views, needs and 
concerns. 


The Coordinating Authority recetrine the-complaint shall assess the complaint and, where 
appropriate, transmit it to the Coordinating Authority of establishment, accompanied, 
where appropriate, by its reasoning. 


Where the complaint falls under the responsibility of another competent authority in its 
Member State, that-desitenated the Coordinating Authority receiving the complaint,that 
Coordinating Authorityshall transmit it to that ethereempetent authority. 

During these proceedings, both parties shall have the right to be heard and receive 
appropriate information about the status of the complaint, in accordance with 
national law. 


33 


PCY comment: copied word for word from Art. 53 of the DSA. 


9317/23 FL/ml 61 
ANNEX JAIILIMITE JIN 


Article 34b34 
Representation 


Without prejudice to Directive (EU) 2020/1828 or to any other type of representation 
under national law, users of relevant information society services shall at least have 
the right to mandate a body, organisation or association to exercise the rights 
conferred by this Regulation on their behalf, provided the body, organisation or 
association meets all of the following conditions: 


(a) it operates on a non-profit basis; 
(b) it has been properly constituted in accordance with the law of a Member State; 


(c) its statutory objectives include a legitimate interest in ensuring that this 
Regulation is complied with. 


Providers of relevant information society services shall take the necessary technical 
and organisational measures to ensure that complaints submitted by bodies, 
organisations or associations referred to in paragraph 1 of this Article on behalf of 
recipients of the service through the mechanisms referred to in Article xx are 
processed and decided upon with priority and without undue delay. 


Article 3535 
Penalties36 


Member States shall lay down the rules on penalties applicable to infringements of the 
obligations pursuant to Chapters II and V of this Regulation by providers of relevant 
information society services within their competence underther jurisdiction and shall 
take all the necessary measures to ensure that they are implemented in accordance with 
Article 27. 


Fhe-pPenalties shall be effective, proportionate and dissuasive. Member States shall, by 
[Date of application of this Regulation], notify the Commission of those rules and of those 
measures and shall notify it, without delay, of any subsequent amendments affecting them. 


34 


35 


36 


PCY comment: copied word for word from Art. 86 of the DSA. To be discussed in relation to 
Articles 18(3) and 34. 


PCY comment: copied word for word from Art. 52 of the DSA (except paragraph 4 that is 
taken from the TCO Regulation). 


PCY comment: this should be understood as administrative sanctions, not criminal sanctions, 
i.e. penalties (TCO and DSA use the wording “penalties” when these are in fact administrative 
sanctions). A recital should be included to clarify this issue. 
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34. 


45. 


Member States shall ensure that the maximum amount of fines that may be penalties 
imposed for an a failure to comply with an obligation laid down in Chapters II and V 
infringementof this Regulation shall be not exceed 6 % of the annual worldwide #wweome 
erelebal turnover of the providers concerned in the preceding financial business-year-of 
the-provider. 3-Member States shall ensure that the maximum amount of the fine that 
may be imposed Penalties for the supply of incorrect, incomplete or misleading 
information, failure to reply or rectify incorrect, incomplete or misleading information er 
and failure to submit to an en-site inspection shall be not exceed 1% of the annual income 
or worldwide glebalturnover of the preceding_business-year-ofthe provider or the-ether 
person concerned in the preceeding financial year-+eferred+ein Article 27. 


Member States shall ensure that the maximum amount of a periodic penalty payment shall 
be not exceed 5 % of the average daily worldwide glebalturnover or income of the 
provider orthe-otherpersonteferred toin Article 27 in the preceding financial year per 
day, calculated from the date specified in the decision concerned. 


Member States shall ensure that the competent authorities, when deciding whether to 
impose a penalty and when determining the type and level of penalty, account is taken of 
all relevant circumstances, including: 


(a) the nature, gravity and duration of the infringement; 

(b) whether the infringement was intentional or negligent; 

(c) an yprevious infringements by the provider or the other person; 

(d) the financial strength of the provider-orthe-other-persen; 

(e) the level of cooperation of the provider with the competent authorities orthe-other 
person, 


(f) the nature and size of the provider-orthe-other-person, in particular whether it is a 
micro, small or medium-sized enterprise; 


(g) the degree of fault of the provider or other person, taking into account the technical 
and organisational measures taken by the provider it-to comply with this Regulation. 
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Section 4 
Cooperation 
Article 36 37 


Identification and submission of online child sexual abuse 


Coordinating Authorities shall submit to the EU Centre, without without undue delay and 
through the system established in accordance with Article 39(2): 


(a) 


(b) 


specific items of material and transeripts extracts of written conversations that 
competent authorities Coordimating—Authorttes or—thatthe—competent judicial 
autherities_or_other independent administrative_autherities of a Member State have 
identified, after a diligent assessment, subject to adequate supervision by judicial 
authorities35, as constituting child sexual abuse material or the solicitation of 
children, as applicable, for the EU Centre to generate indicators in accordance with 
Article 44(3); 


exact uniform resource locators indicating the electronic location of the 


information oe that Rein ae authorities pacers 


authorities of a Member State have identified, after a diligent assessment, as 


ee child sexual abuse material, El din, ‘Se ERS 


suilotitie: of he Ghd cute ia Mgt the BU ais to ee the 


list of uniform resource locators in accordance with Article 44(3); 


Member States shall take the necessary measures to ensure that the Coordinating 
Authorities that they designated receive, without undue delay, the material identified as 
child sexual abuse material, the transcripts extracts of written conversations identified as 
the solicitation of children, and the uniform resource locators, identified a a Senay 


authority a 


fis Caseincune Aqinca’™ for sabriiesion to the EU ee in aueconance ‘with the first 
subparagraph. 


37 


38 


PCY comment: the LEWP should continue working on this Article and return to it once more 


clarity is reached on the detection orders. 


The Commission has provided a text proposal to make clear that law enforcement can be 
involved in the process to determine the illegality of the content, under judicial supervision 


(recital xx “Member States should set up expedited procedures for the diligent 


assessment of suspected child sexual abuse, so as to allow for the swift submission to the 
EU Centre of the specific items of material, transcripts extracts of written conversations 


and uniform resource locators concerned upon the reliable establishment of the 
illegality. With a view to facilitating and expediting such assessment, it should be 


possible for Member States to provide that competent authorities may carry out the 
assessment of illegality of the content, under the supervision of the competent judicial 


authorities or independent administrative authorities.”). 
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la. 


By deviation from paragraph 1, Member States may decide that the submission to the 
EU Centre referred to in points a) and b) of paragraph 1 can be carried out by the 
competent authorities without undue delay and through the system established in 
accordance with Article 39(2). Where a Member State is making use of this 
possibility, the competent authority shall include inform the Coordinating Authority 
in of all the correspondence with the EU Centre. 


Upon the request of the EU Centre where necessary to ensure that the data contained in the 
databases referred to in Article 44(1) are complete, accurate and up-to-date, Coordinating 
Authorities shall verify or provide clarifications or additional information as to whether the 
conditions of paragraph 1, points (a) and (b) have been and, where relevant, continue to be 
met, in respect of a given submission to the EU Centre in accordance with that paragraph. 


Member States shall ensure that, where their law enforcement authorities receive a report 
of the dissemination of new child sexual abuse material or of the solicitation of children 
forwarded to them by the EU Centre in accordance with Article 48(3), a diligent 
assessment is conducted in accordance with paragraph 1 and, if the material or 
conversation is identified as constituting child sexual abuse material or as the solicitation 
of children, the Coordinating Authority submits the material to the EU Centre, in 
accordance with that paragraph, within ene two months from the date of reception of the 
report or, where the assessment is particularly complex, #¥e six months from that date. 


They shall also ensure that, where the diligent assessment indicates that the material does 
not constitute child sexual abuse material or the solicitation of children, the Coordinating 
Authority is informed of that outcome and subsequently informs the EU Centre thereof, 
within the time periods specified in the first subparagraph. 


Article 3749 
Cross-border cooperation among Coordinating Authorities 


Where a Coordinating Authority that is not the Coordinating Authority of establishment 
has reasons to suspect that a provider of relevant information society services infringed this 
Regulation in a manner negatively affecting the users of the service in the Member 
State of that Coordinating Authority, it may shaH-request the Coordinating Authority of 
establishment to assess the matter and to take the necessary investigatory and enforcement 
measures to ensure compliance with this Regulation. 
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PCY comment: implications for law enforcement workload to be considered. 


PCY comment: copied word for word from Art. 58 of the DSA. 
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Wherethe-Commnission_has_reasons_te—suspect that a_provider_of relevant information 
seciety_services_infringed this Resulation in_amannerinveline atleast three Member 


States, it may_treconmmend that the Coordinating Authority _of establishment_assess_the 
matter—and_take the _necessary—investigatory—and_enforcement_measures—to—ensure 


The A request er recommendation pursuant referred to in paragraph | shall be duly 
reasoned and at least indicate: 


(a) the point of contact of the provider as set out in Article 23; 


(b) a description of the relevant facts, the provisions of this Regulation concerned and 
the reasons why the Coordinating Authority that sent the requesterthe-Commissien 
suspects, that the provider infringed this Regulation including the description of the 
negative effects of the alleged infringement; 


(c) any other information that the Coordinating Authority that sent the request—erthe 
Coramissien, considers relevant, including, where appropriate, information gathered 
on its own initiative aad or suggestions for specific investigatory or enforcement 
measures to be taken, including interim measures. 


The Coordinating Authority of establishment shall take utmost account of the requests 
aay to eee 1 of this a rs. 

A aph_t. Where it 
Sosles that it has iaeufticieat ‘aieaatone to ee Bee eer 
upon the request er-recemmendation and has reasons to consider that the Coordinating 
Authority that sent the request,erthe- Commission, could provide additional information, it 
may request such information. The time period laid down in paragraph 4 shall be 
suspended until that additional information is provided. 


The Coordinating Authority of establishment shall, without undue delay and in any event 
not later than two months following receipt of the request errecommendation pursuant 
referred_to in-paragraph 1, communicate to the Coordinating Authority that sent the 
sa aa seep ages, the outcome-of its assessment of the apis sess Sues 
: iy vant, and; 
sists anelicas®) an Mpianation of the iavesinaton) or  eafoReemieat measures taken or 
envisaged in relation thereto to ensure compliance with this Regulation. 


9317/23 FL/ml 66 
ANNEX JAILILIMITE JIN 


Article 3841 
Joint investigations 


Coordinating Authorities may participate in joint investigations, which may be coordinated 
with the support of the EU Centre, of matters covered by this Regulation, concerning 
providers of relevant information society services that offer their services in several 
Member States. 


Such joint investigations are without prejudice to the tasks and powers of the participating 
Coordinating Authorities and the requirements applicable to the performance of those tasks 
and exercise of those powers provided for in this Regulation. 


The participating Coordinating Authorities shall make the results of the joint investigations 
available to other Coordinating Authorities, the Commission and the EU Centre, through 
the system established in accordance with Article 39(2), for the fulfilment of their 
respective tasks under this Regulation. 


Article 38a? 
Mutual assistance 


The Coordinating Authorities, the competent authorities of the Member States and the 
EU Centre Digital_Services-Coordinaters_and_the—Commission-shall cooperate closely 
and provide each other with mutual assistance in order to apply this Regulation in a 
consistent and efficient manner. Mutual assistance shall include, in particular, 
exchange of information in accordance with this Article and the duty of the Digital 
SAS SENOS SEES iy rdinating ees to Iona all 
Coordinating Authorities Di ; ; 4, the 6 

the-Commiission about the opening of an investigation and the intention to take a final 
decision, including its assessment, in respect of a specific provider of a relevant 


information society intermediary service. 
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PCY comment: recital to be added, as follows: “Joint investigations” under Article 38 
should be interpreted as formal inquiries by Coordinating Authorities concerning the 
compliance of the provider of relevant information society services with the obligations 
arising from this Regulation. Insofar as the penalties for infringements of those 
obligations provided for by the Member State concerned pursuant to this Regulation are 
not criminal in nature, “joint investigations” under Article 38 should not be interpreted 
as criminal investigations, which are usually conducted by law enforcement authorities 
under national law.” 


Copied from Article 57 of the DSA (changes vis-a-vis the DSA in italics). 
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For the purpose of an investigation, a Coordinating Authority the Digital_Services 


Coordinaterof-establishment may request a Coordinating Authority in another Member 
State ether—Digital_Services—Coordinators to provide specific information in their 


possession as regards a specific provider of relevant information society intermediary 
services or to exercise their investigative powers referred to in Article 27 544) with 
regard to specific information located in their Member State. Where appropriate, the 
Coordinating Authority Digital Services-Coordinator receiving the request may involve 
other competent authorities or other public authorities of the Member State in 
question. 


The Coordinating Authority Digital—Serviees—Coerdinater receiving the request 
pursuant to paragraph 2 shall comply with such request and inform the requesting 
Coordinating Authority Digital Services-Coordinator_of_establishment about the action 
taken, without undue delay and netaterthantwe-months-after its receipt, unless: 


(a) the scope or the subject matter of the request is not sufficiently specified, 
justified or proportionate in view of the investigative purposes; or 


(b) neither the requested Coordinating Authority Digital _Service—Coordinater nor 


other competent authority or other public authority of that Member State is in 
possession of the requested information nor can have access to it; or 


(c) the request cannot be complied with without infringing Union or national law. 


The Digital Services_Cooerdinater Coordinating Authority receiving the request shall 


justify its refusal by submitting a reasoned reply, within the period set out in the first 
subparagraph. 


Article 39 


GeneraleCooperation, coordination and information-sharing system 


Competent authorities ~~ shall ae sa with each 
other, eth 4 


Authority, the Congicsion the EU Centre and thes “éleyatit Union agencies, ‘aida 
Europol, to facilitate the performance of their respective tasks under this Regulation and to 
ensure its effective, efficient and consistent application and enforcement, without 
prejudice to the possibility for Member States to provide for cooperation mechanisms 
and regular exchanges of views between the competent authorities where relevant for 
the performance of their respective tasks in accordance with this Regulation. 
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la. The authorities and agencies referred to in paragraph 1 may shall, including with the 
support from the EU Centre, coordinate their work under this Regulation with a view 
to avoiding interference with criminal investigations in different Member States and 
to avoiding duplication of efforts. 


2; The EU Centre shall establish and maintain one or more reliable and secure information 
sharing systems supporting communications between competent authorities Coordinating 
Authorities, the Commission, the EU Centre, other relevant Union agencies and providers 
of relevant information society services. 


2a. The information sharing system or systems referred to in paragraph 2 shall facilitate 
compliance with the obligations set out in Article 83(2) collecting in an automated 
manner and enabling an easy retrieving of relevant statistical information. 


3. The competent authorities Coordinating Authorities, the Commission, the EU Centre, 
other relevant Union agencies and providers of relevant information society services shall 


use the information-sharing systems referred to in paragraph 2 for all relevant 
communications pursuant to this Regulation. 


4. The Commission shall adopt implementing acts laying down the practical and operational 
arrangements for the functioning of the information-sharing systems referred to in 
paragraph 2 and their interoperability with other relevant systems. Those implementing 
acts shall be adopted in accordance with the advisory procedure referred to in Article 87. 
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CHAPTER IV 


EU CENTRE TO PREVENT AND COMBAT CHILD SEXUAL ABUSE 
Section 1 
Principles 
Article 40 
Establishment and scope of action of the EU Centre 


A European Union Agency to prevent and combat child sexual abuse, the EU Centre on 
Child Sexual Abuse, is established. 


The EU Centre shall contribute to the achievement of the objective of this Regulation by 
supporting and facilitating the implementation of its provisions concerning the detection, 
reporting, removal or disabling of access to, and blocking of online child sexual abuse and 
gather and share information and expertise and facilitate cooperation between relevant 
public and private parties in connection to the prevention and combating of child sexual 
abuse, in particular online. 


Article 41 
Legal status 
The EU Centre shall be a body of the Union with legal personality. 


In each of the Member States the EU Centre shall enjoy the most extensive legal capacity 
accorded to legal persons under their laws. It may, in particular, acquire and dispose of 
movable and immovable property and be party to legal proceedings. 


The EU Centre shall be represented by its Executive Director. 


Article 42 


Seat 


The seat of the EU Centre shall be The Hague, The Netherlands. 


9317/23 FL/ml 70 
ANNEX JALILIMITE JIN 


Section 2 
Tasks 
Article 43 
Tasks of the EU Centre 


The EU Centre shall: 


(1) 


(2) 


(3) 


(4) 


facilitate the risk assessment process referred to in Section | of Chapter II, by: 


(a) supporting the Commission in the preparation of the guidelines referred to in Article 
3(8), Article 4(5), Article 6(4) and Article 11, including by collecting and providing 
relevant information, expertise and best practices, taking into account advice from 
the Technology Committee referred to in Article 66; 


(b) upon request from a provider of relevant information services, providing an analysis 
of anonymised data samples for the purpose referred to in Article 3(3); 


facilitate the detection process referred to in Section 2 of Chapter II, by: 


(a) providing the opinions on intended detection orders referred to in Article 7(3), first 
subparagraph, point (d); 


(b) maintaining and operating the databases of indicators referred to in Article 44; 


(c) giving providers of hosting services and providers of interpersonal communications 
services that received a detection order access to the relevant databases of indicators 
in accordance with Article 46; 


(d) making technologies available to providers for the execution of detection orders 
issued to them, in accordance with Article 50(1); 


facilitate the reporting process referred to in Section 3 of Chapter I, by: 
(a) maintaining and operating the database of reports referred to in Article 45; 


(b) assessing, processing and, where necessary, forwarding the reports and providing 
feedback thereon in accordance with Article 48; 


facilitate the removal process referred to in Section 4 of Chapter II and the other processes 
referred to in Section 5, 5a and 6 of that Chapter, by: 


(a) receiving the removal orders transmitted to it pursuant to Article 14(4) in order to 
fulfil the verification function referred to in Article 49(1); 
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(5) 


receiving decisions on a cross-border removal order transmitted to it pursuant 
to Article 14a(5); 


receiving copies of final removal orders and thereto connected information 
transmitted to it pursuant to Article 15(2); 


cooperatine —with—and_respondine_te—_requests—of Coordinating Authorities in 
connection te intended blocking orders_as referred toin Article 162); 


receiving and processing the blocking orders transmitted to it pursuant to Article 
17(3); 


receiving copies of final blocking orders and thereto connected information 
transmitted to it pursuant to Article 18(2); 


receiving the delisting orders transmitted to it pursuant to Article 18b(2); 


receiving copies of final delisting orders and thereto connected information 
transmitted to it pursuant to Article 18c(3); 


providing information and support to victims in accordance with Articles 20 and 21; 


maintaining up-to-date records of contact points and legal representatives of 
providers of relevant information society services as provided in accordance with 
Article 23(2) and Article 24(6); 


support the competent authorities, including the Coordinating Authorities, and the 
Commission in the performance of their tasks under this Regulation and facilitate 
cooperation, coordination and communication in connection to matters covered by this 
Regulation, by: 


(a) 


(d) 


creating and maintaining an online register listing the Coordinating Authorities and 
their contact points referred to in Article 25(6); 


providing assistance to the Coordinating Authorities free of charge and in 
accordance with its tasks and obligations under this Regulation as-provided fer 
‘ele 25(D); 

assisting the Commission, upon its request, in connection to its tasks under the 


cooperation mechanism referred to in Article 37; 


creating, maintaining and operating the information-sharing system referred to in 
Article 39; 
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(6) 


(e) 


(f) 


assisting the Commission in the preparation of the delegated and implementing acts 
and the guidelines that the Commission adopts under this Regulation; 


providing information to Coordinating Authorities, upon their request or on its own 
initiative, relevant for the performance of their tasks under this Regulation, including 
by informing the Coordinating Authority of establishment of potential infringements 
identified in the performance of the EU Centre’s other tasks; 


facilitate the generation and sharing of knowledge with other Union institutions, bodies, 
offices and agencies, competent authorities including Coordinating Authorities, or other 
relevant authorities of the Member States to contribute to the achievement of the objective 
of this Regulation, by: 


(a) 


(b) 


(c) 


collecting, recording, analysing and providing information, providing analysis based 
on anonymised and non-personal data gathering, and providing expertise on matters 
regarding the prevention and combating of online child sexual abuse, in accordance 
with Article 51; 


supporting the development and dissemination of research and expertise on those 
matters and on assistance to victims, including by serving as a hub of expertise to 
support evidence-based policy; 


drawing up the annual reports referred to in Article 84. 
Article 44 


Databases of indicators 


The EU Centre shall create, maintain and operate databases of the following three types of 
indicators of online child sexual abuse: 


(a) 


(b) 


(c) 


indicators to detect the dissemination of child sexual abuse material previously 
detected and identified as constituting child sexual abuse material in accordance with 
Article 36(1); 


indicators to detect the dissemination of child sexual abuse material not previously 
detected and identified as constituting child sexual abuse material in accordance with 
Article 36(1); 


indicators to detect the solicitation of children. 


The databases of indicators shall solely contain: 


(a) 


relevant indicators, consisting of digital identifiers to be used to detect the 
dissemination of known or new child sexual abuse material or the solicitation of 
children, as applicable, on hosting services and interpersonal communications 
services, generated by the EU Centre in accordance with paragraph 3; 
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(b) as regards paragraph 1, point (a), the relevant indicators shall include a lists of 
uniform resource locators compiled by the EU Centre in accordance with paragraph 
3 for the purpose of, respectively, the issuance of blocking orders in accordance 
with Article 16 and the issuance of delisting orders in accordance with Article 
18a; 


(c) the necessary additional information to facilitate the use of the indicators in 
accordance with this Regulation, including identifiers allowing for a distinction 
between images, videos and, where relevant, other types of material for the detection 
of the dissemination of known and new child sexual abuse material and language 
identifiers for the detection of solicitation of children. 


The EU Centre shall generate the indicators referred to in paragraph 2, point (a), solely on 
the basis of the child sexual abuse material and the solicitation of children identified as 
such by the Coordinating Authorties competent authorities of the Member States, 
submitted to it by the Coordinating Authorities pursuant to Article 36(1), point (a), or by 
other competent authorities pursuant to Article 36(1a). 


The EU Centre shall compile the lists of uniform resource locators referred to in paragraph 
2, point (b), solely on the basis of the uniform resource locators submitted to it pursuant to 
Article 36(1), point (b) for the purpose of, respectively, the issuance of blocking orders 
in accordance of Article 16 and the issuance of delisting orders in accordance with 
Article 18a. 


The EU Centre shall keep records of the submissions and of the process applied to generate 
the indicators and compile the lists referred to in the first and second subparagraphs. It 
shall keep those records for no longer than as+tere-as-the indicators, including the uniform 
resource locators, to which they correspond are contained in the databases of indicators 
referred to in paragraph 1. 


Article 45 
Database of reports 


The EU Centre shall create, maintain and operate a database for the reports submitted to it 
by providers of hosting services and providers of interpersonal communications services in 
accordance with Article 12(1) and assessed and processed in accordance with Article 48. 


The database of reports shall contain the following information: 
(a) the report; 


(b) where the EU Centre considered the report manifestly unfounded, the reasons and 
the date and time of informing the provider in accordance with Article 48(2); 
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(c) where the EU Centre forwarded the report in accordance with Article 48(3), the date 
and time of such forwarding and the name of the competent law enforcement 
authority or authorities to which it forwarded the report or, where applicable, 
information on the reasons for forwarding the report solely to Europol for further 
analysis; 


(d) where applicable, information on the requests for and provision of additional 
information referred to in Article 48(5); 


(e) where available, information indicating that the provider that submitted a report 
concerning the dissemination of known or new child sexual abuse material removed 
or disabled access to the material; 


(f) where applicable, information on the EU Centre’s request to the Ceordimatine 
Authority competent authority of establishment to issue a removal order pursuant 
to Article 14 in relation to the item or items of child sexual abuse material to which 
the report relates; 


(g) relevant indicators and ancillary tags associated with the reported potential child 
sexual abuse material. 


Article 46 
Access, accuracy and security 


Subject to paragraphs 2 and 3, solely EU Centre staff and auditors duly authorised by the 
Executive Director shall have access to and be entitled to process the data contained in the 
databases referred to in Articles 44 and 45. 


The EU Centre shall give providers of hosting services, providers of interpersonal 
communications services, and providers of internet access services and providers of 
online search engines access to the databases of indicators referred to in Article 44, where 
and to the extent necessary for them to execute the detection or blocking orders that they 
received in accordance with Articles 7 or 16. It shall take measures to ensure that such 
access remains limited to what is strictly necessary for the period of application of the 
detection or blocking orders concerned and that such access does not in any way endanger 
the proper operation of those databases and the accuracy and security of the data contained 
therein. 
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The EU Centre shall give Coordinating Authorities competent authorities access to the 
databases of indicators referred to in Article 44 where and to the extent necessary for the 
performance of their tasks under this Regulation. 


The EU Centre shall give Europol and the competent law enforcement authorities of the 
Member States access to the databases of indicators referred to in Article 44 where and to 
the extent necessary for the performance of their tasks of investigating suspected child 
sexual abuse offences43. 


The EU Centre shall give Europol access to the databases of reports referred to in Article 
45, where and to the extent necessary for the performance of its tasks of assisting 
investigations of suspected child sexual abuse offences 


The EU Centre shall provide the access referred to in paragraphs 2, 3, 4 and 5 only upon 
the reception of a request, specifying the purpose of the request, the modalities of the 
requested access, and the degree of access needed to achieve that purpose. The requests for 
the access referred to in paragraph 2 shall also include a reference to the detection order or 
the blocking order, as applicable. 


The EU Centre shall diligently assess those requests and only grant access where it 
considers that the requested access is necessary for and proportionate to the specified 


purpose. 


The EU Centre shall regularly verify that the data contained in the databases referred to in 
Articles 44 and 45 is, in all respects, complete, accurate and up-to-date and continues to be 
necessary for the purposes of reporting, detection and blocking in accordance with this 
Regulation, as well as facilitating and monitoring of accurate detection technologies and 
processes. In particular, as regards the uniform resource locators contained in the database 
referred to Article 44(1), point (a), the EU Centre shall, where necessary in cooperation 
with the Coordination Authorities, regularly verify that the conditions of Article 36(1), 
point (b), continue to be met. Those verifications shall include audits, where appropriate. 
Where necessary in view of those verifications, it shall immediately complement, adjust or 
delete the data. 


43 


PCY comment : the PCY considers it necessary to include a recital outlining possible criteria 
concerning access refusal and justification thereof. 
PCY comment: new recital to be included: “Considering its role as central knowledge hub 


on matters related to the implementation of this Regulation at EU level, the EU Centre 
should leverage all means at its disposal to support the work of Europol and competent 
law enforcement authorities, for example by ensuring that information received by law 
enforcement authorities is relevant, complete and as easy as possible to access and 
consult. In particular, the EU Centre should give Europol and the competent law 
enforcement authorities of the Member States access to the database of indicators when 
necessary for the purpose of their tasks of investigating suspected child sexual abuse 
offences. This includes when law enforcement authorities need that access to verify 
whether certain items that are relevant in the context of national investigations have 


already been identified as online child sexual abuse, hashed and included in the 
database.” 
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The EU Centre shall ensure that the data contained in the databases referred to in Articles 
44 and 45 is stored in a secure manner and that the storage is subject to appropriate 
technical and organisational safeguards. Those safeguards shall ensure, in particular, that 
the data can be accessed and processed only by duly authorised persons for the purpose for 
which the person is authorised and that a high level of security is achieved. The EU Centre 
shall regularly review those safeguards and adjust them where necessary. 


Article 47 


Delegated acts relating to the databases 


The Commission shall be empowered to adopt delegated acts in accordance with Article 86 in order 
to supplement this Regulation with the necessary detailed rules concerning: 


(a) 


(b) 


(c) 


(d) 


(e) 


the types, precise content, set-up and operation of the databases of indicators referred to in 
Article 44(1), including the indicators and the necessary additional information to be 
contained therein referred to in Article 44(2); 


the processing of the submissions by Coordinating Authorities, the generation of the 
indicators, the compilation of the lists of uniform resource locators and the record-keeping, 
referred to in Article 44(3); 


the precise content, set-up and operation of the database of reports referred to in Article 
45(1); 


access to the databases referred to in Articles 44 and 45, including the modalities of the 
access referred to in Article 46(1) to (5), the content, processing and assessment of the 
requests referred to in Article 46(6), procedural matters related to such requests and the 
necessary measures referred to in Article 46(6); 


the regular verifications and audits to ensure that the data contained in those databases is 
complete, accurate and up-to-date referred to in Article 46(7) and the security of the 
storage of the data, including the technical and organisational safeguards and regular 
review referred to in Article 46(8). 


Article 48 
Reporting 


The EU Centre shall expeditiously assess and process reports submitted by providers of 
hosting services and providers of interpersonal communications services in accordance 
with Article 12 to determine whether the reports are manifestly unfounded or are to be 
forwarded. 


Where the EU Centre considers that the report is manifestly unfounded, it shall inform the 
provider that submitted the report, specifying the reasons why it considers the report to be 
unfounded. 
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Where the EU Centre-considers that there are reasonsable grounds for the EU Centre to 
consider that the a report is netmanHesth—unfounded, it shall forward the report, together 
with any additional relevant information available to it, to Europol and to the competent 
law enforcement authority or authorities of the Member State likely to have jurisdiction to 
investigate or prosecute the potential child sexual abuse to which the report relates. 


Where that competent law enforcement authority or those competent law enforcement 
authorities cannot be determined with sufficient certainty, the EU Centre shall forward the 
report, together with any additional relevant information available to it, to Europol, for 
further analysis and subsequent referral by Europol to the competent law enforcement 
authority or authorities. 


Where-a_provider that submitted the report has indicated that the report requires_urcent 
action, the EU Centre shall assess-and process that report as-_amatter of priority and where 
it_forwards_the report in_accordance -with_parasraph 3 and it _considers_that the report 


The EU Centre shall perform the assessment and processing referred to in 
paragraphs 1, 2 and 3 of this Article as a matter of priority in respect of reports 
submitted in accordance with Article 13(2), first subparagraph. In particular, where 
there are reasonsable grounds for the EU Centre to consider that the report is 
founded and that there is likely to be an imminent threat to the life or safety of a child 
including when the report indicates ongoing abuse, it shall immediately forward the 
report in accordance with paragraph 3, marking it as requiring urgent action. 


Where the EU Centre considers, in respect of a report submitted in accordance with 
Article 13(2), first subparagraph, that there is not likely to be an imminent threat to 
the life of a child including when the report does not indicate ongoing abuse, it shall 
indicate that when forwarding the report in accordance with paragraph 3 and it shall 
also inform the provider that submitted the report and the competent authority, 
specifying in all cases the reasons why it considers that there is not likely to be an 
imminent threat to the life of a child. 


Where the report does not contain all the information required in Article 13, the EU Centre 
may request the provider that submitted the report to provide the missing information. 


Where so requested by a competent law enforcement authority of a Member State in order 
to avoid interfering with activities for the prevention, detection, investigation and 
prosecution of child sexual abuse offences, the EU Centre shall: 


(a) communicate to the provider that submitted the report that it is not to inform the user 
concerned, specifying the time period during which the provider is not to do so; 


(b) where the provider that submitted the report is a provider of hosting services and the 
report concerns the potential dissemination of child sexual abuse material, 
communicate to the provider that it is not to remove or disable access to the material, 
specifying the time period during which the provider is not to do so. 
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The time periods referred to in the first subparagraph, points (a) and (b), shall be those 
specified in the competent law enforcement authority’s request to the EU Centre, provided 
that they remain limited to what is necessary to avoid interference with the relevant 
activities and does not exceed 18 months. 


The EU Centre shall verify whether a provider of hosting services that submitted a report 
concerning the potential dissemination of child sexual abuse material removed or disabled 
access to the material, insofar as the material is publicly accessible. Where it considers that 
the provider did not remove or disable access to the material expeditiously, the EU Centre 
shall inform the Coordinating Authority of establishment thereof. 


Article 49 
Searches and notification 


The EU Centre shall have the power to conduct searches on hosting services for the 
dissemination of publicly accessible child sexual abuse material, using the relevant 
indicators from the database of indicators referred to in Article 44(1), points (a) and (b), in 
the following situations: 


(a) where so requested to support a victim by verifying whether the provider of hosting 
services removed or disabled access to one or more specific items of known child 
sexual abuse material depicting the victim, in accordance with Article 21(4), point 
(c); 

(b) where so requested to assist a CoordinatineAuthorty competent authority by 
verifying the possible need for the issuance of a-detection-erderer a removal order in 
respect of a specific service erthe-effectiveness_ofadetection_orderora+removal 


order thatthe Coordinatine Authority issued, in accordance with Article 25(7), points 
(c) and (d), respectively; 


(c) where so requested to assist a Coordinating Authority, by verifying the 
effectiveness of a detection order that the competent judicial authorities or other 
independent administrative authorities issued, in accordance with Article 25(7), 
point (d). 


The EU Centre shall have the power to notify, after having conducted the searches referred 
to in paragraph 1, providers of hosting services of the presence of one or more specific 
items of known child sexual abuse material on their services and request them to remove or 
disable access to that item or those items, for the providers’ voluntary consideration. 


The request shall clearly set out the identification details of the EU Centre and a contact 
point, the necessary information for the identification of the item or items, as well as the 
reasons for the request. The request shall also clearly state that it is for the provider’s 
voluntary consideration. 


9317/23 FL/ml 79 
ANNEX JALILIMITE JIN 


Where so requested by a competent law enforcement authority of a Member State in order 
to avoid interfering with activities for the prevention, detection, investigation and 
prosecution of child sexual abuse offences, the EU Centre shall not submit a notice, for as 
long as necessary to avoid such interference but no longer than 18 months. 


Article 50 
Technologies, information and expertise 


The EU Centre shall make available technologies that providers of hosting services and 
providers of interpersonal communications services may acquire, install and operate, free 
of charge, where relevant subject to reasonable licensing conditions, to execute detection 
orders in accordance with Article 10(1). 


To that aim, the EU Centre shall compile lists of such technologies, having regard to the 
requirements of this Regulation and in particular those of Article 10(2). 


Before including specific technologies on those lists, the EU Centre shall request the 
opinion of its Technology Committee and of the European Data Protection Board. The 
Technology Committee and the European Data Protection Board shall deliver their 
respective opinions within eight weeks. That period may be extended by a further six 
weeks where necessary, taking into account the complexity of the subject matter. The 
Technology Committee and the European Data Protection Board shall inform the EU 
Centre of any such extension within one month of receipt of the request for consultation, 
together with the reasons for the delay. 


The EU Centre shall collect, record, analyse and make available relevant, objective, 
reliable and comparable information on matters related to the prevention and combating of 
child sexual abuse, in particular: 


(a) information obtained in the performance of its tasks under this Regulation 
concerning detection, reporting, removal or disabling of access to, and blocking of 
online child sexual abuse; 


(b) information resulting from the research, surveys and studies referred to in paragraph 
3; 


(c) information resulting from research or other activities conducted by Member States’ 
authorities, other Union institutions, bodies, offices and agencies, the competent 
authorities of third countries, international organisations, research centres and civil 
society organisations. 
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Where necessary for the performance of its tasks under this Regulation, the EU Centre 
shall carry out, participate in or encourage research, surveys and studies, either on its own 
initiative or, where appropriate and compatible with its priorities and its annual work 
programme, at the request of the European Parliament, the Council or the Commission. 


The EU Centre shall provide the information referred to in paragraph 2 and the information 
resulting from the research, surveys and studies referred to in paragraph 3, including its 
analysis thereof, and its opinions on matters related to the prevention and combating of 
online child sexual abuse to other Union institutions, bodies, offices and agencies, 
Coordinating Authorities, other competent authorities and other public authorities of the 
Member States, either on its own initiative or at request of the relevant authority. Where 
appropriate, the EU Centre shall make such information publicly available. 


The EU Centre shall develop a communication strategy and promote dialogue with civil 
society organisations and providers of hosting or interpersonal communication services to 
raise public awareness of online child sexual abuse and measures to prevent and combat 
such abuse. 


Section 3 
Processing of information 
Article 51 
Processing activities and data protection 


In so far as is necessary for the performance of its tasks under this Regulation, the EU 
Centre may process personal data. 


The EU Centre shall process personal data as strictly necessary for the purposes of: 
(a) providing the opinions on intended detection orders referred to in Article 7(3); 


(b) cooperating with and responding to requests of Coordinating Authorities in 
connection to intended blocking orders as referred to in Article 16(2); 


(c) receiving and processing blocking orders transmitted to it pursuant to Article 17(3); 


(d) cooperating with Coordinating Authorities in accordance with Articles 20 and 21 on 
tasks related to victims’ rights to information and assistance; 
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(e) 


(f) 


(0) 


maintaining up-to-date records of contact points and legal representatives of 
providers of relevant information society services as provided in accordance with 
Article 23(2) and Article 24(6); 


creating and maintaining an online register listing the Coordinating Authorities and 
their contact points referred to in Article 25(6); 


providing assistance to Coordinating Authorities in accordance with Article 25(7); 


assisting the Commission, upon its request, in connection to its tasks under the 
cooperation mechanism referred to in Article 37; 


create, maintain and operate the databases of indicators referred to in Article 44; 
create, maintain and operate the database of reports referred to in Article 45; 


providing and monitoring access to the databases of indicators and of reports in 
accordance with Article 46; 


performing data quality control measures in accordance with Article 46(7); 


assessing and processing reports of potential online child sexual abuse in accordance 
with Article 48; 


cooperating with Europol and partner organisations in accordance with Articles 53 
and 54, including on tasks related to the identification of victims; 


generating statistics in accordance with Article 83. 


The EU Centre shall store the personal data referred to in paragraph 2 only where and for 
as long as strictly necessary for the applicable purposes listed in paragraph 2. 


It shall ensure that the personal data is stored in a secure manner and that the storage is 
subject to appropriate technical and organisational safeguards. Those safeguards shall 
ensure, in particular, that the personal data can be accessed and processed only for the 
purpose for which it is stored, that a high level of security is achieved and that the personal 
data is deleted when no longer strictly necessary for the applicable purposes. It shall 
regularly review those safeguards and adjust them where necessary. 
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Section 4 
Cooperation 
Article 52 
Contact officers 


Each Coordinating Authority shall designate at least one contact officer, who shall be the 
main contact point for the EU Centre in the Member State concerned. The contact officers 
may be seconded to the EU Centre. Where several contact officers are designated, the 
Coordinating Authority shall designate one of them as the main contact officer. 


Contact officers shall assist in the exchange of information between the EU Centre and the 
Coordinating Authorities that designated them. Where the EU Centre receives reports 
submitted in accordance with Article 12 concerning the potential dissemination of new 
child sexual abuse material or the potential solicitation of children, the contact officers 
designated by the competent Member State shall facilitate the process to determine the 
illegality of the material or conversation, in accordance with Article 36(1). 


The Management Board shall determine the rights and obligations of contact officers in 
relation to the EU Centre. Contact officers shall enjoy the privileges and immunities 
necessary for the performance of their tasks. 


Where contact officers are seconded to the EU Centre, the EU Centre shall cover the costs 
of providing them with the necessary premises within the building and adequate support 
for contact officers to perform their duties. All other costs that arise in connection with the 
designation of contact officers and the performance of their tasks shall be borne by the 
Coordinating Authority that designated them. 


Article 5344 
Cooperation with Europol 


Where necessary for the performance of its tasks under this Regulation, within their 
respective mandates, the EU Centre shall cooperate with Europol. 


Europol and the EU Centre shall provide each other with the fullest possible access to 
relevant information and information systems, where necessary for the performance of 
their respective tasks and in accordance with the acts of Union law regulating such access. 


44 


PCY comment : the PCY noted several questions from delegations on this Article and would 
welcome text proposals from delegations. 
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Without prejudice to the responsibilities of the Executive Director, the EU Centre shall 
maximise efficiency by sharing administrative functions with Europol, including functions 
relating to personnel management, information technology (IT) and budget 


implementation. 
3. The terms of cooperation and working arrangements shall be laid down in a memorandum 
of understanding. 
Article 54 
Cooperation with partner organisations 
Le Where necessary for the performance of its tasks under this Regulation, the EU Centre may 


cooperate with organisations and networks with information and expertise on matters 
related to the prevention and combating of online child sexual abuse, including civil 
society organisations and semi-public organisations. 


2: The EU Centre may conclude memoranda of understanding with organisations referred to 
in paragraph 1, laying down the terms of cooperation, including on data sharing. 


Section 5 
Organisation 
Article 55 
Administrative and management structure 
The administrative and management structure of the EU Centre shall comprise: 
(a) a Management Board, which shall exercise the functions set out in Article 57; 
c we Board-which-shalfoerk ‘ele 62:45 


(c) an Executive Director of the EU Centre, who shall exercise the responsibilities set 
out in Article 64; 


(d) a Technology Committee as an advisory group, which shall exercise the tasks set out 
in Article 66. 


45 PCY comment : it seems to the PCY that several delegations oppose the establishment of an 
Executive Board. If the Executive Board is removed from the text, further text alignments 
will be needed, including reallocation of tasks etc. 
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Part 1: Management Board 


Article 56 
Composition of the Management Board 


The Management Board shall be composed of one representative from each Member State 
and two representatives of the Commission, all as members with voting rights. 


The Management Board shall also include one independent expert observer designated by 
the European Parliament, without the right to vote. 


Europol may designate a representative to attend the meetings of the Management Board 
as an observer on matters involving Europol, without the right to vote, at the request of 
the Chairperson of the Management Board. 


Each member of the Management Board shall have an alternate. The alternate shall 
represent the member in his/her absence. 


Members of the Management Board and their alternates shall be appointed in the light of 
their knowledge in the field of combating child sexual abuse, taking into account relevant 
managerial, administrative and budgetary skills. Member States shall appoint a 
representative of their Coordinating Authority, within four months of [date of entry into 
force of this Regulation]. All parties represented in the Management Board shall make 
efforts to limit turnover of their representatives, in order to ensure continuity of its work. 
All parties shall aim to achieve a balanced representation between men and women on the 
Management Board. 


The term of office for members and their alternates shall be four years. That term may be 
renewed. 


Article 57 
Functions of the Management Board 
The Management Board shall: 
(a) give the general orientations for the EU Centre's activities; 


(b) contribute to facilitate the effective cooperation with and between the Coordinating 
Authorities; 
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(c) adopt rules for the prevention and management of conflicts of interest in respect of 
its members, as well as for the members of the Technological Committee and of any 
other advisory group it may establish and publish annually on its website the 
declaration of interests of the members of the Management Board. The consent of 
its members must be obtained prior to publication; 


(d) adopt the assessment of performance of the Executive Board referred to in Article 
61(2); 
(e) adopt and make public its Rules of Procedure; 


(f) appoint the members of the Technology Committee, and of any other advisory group 
it may establish; 


(fa) consult the Victims Board in all cases where, in the performance of its tasks 
pursuant to points (a) and (h), interests of victims are concerned; 


(g) adopt the opinions on intended detection orders referred to in Article 7(4), on the 
basis of a draft opinion provided by the Executive Director; 


(h) adopt and regularly update the communication and dissemination plans referred to in 
Article 77(3) based on an analysis of needs. 


Article 58 
Chairperson of the Management Board 


The Management Board shall elect a Chairperson and a Deputy Chairperson from among 
its members. The Chairperson and the Deputy Chairperson shall be elected by a majority 
of two thirds of the members of the Management Board. 


The Deputy Chairperson shall automatically replace the Chairperson if he/she is prevented 
from attending to his/her duties. 


The term of office of the Chairperson and the deputy Chairperson shall be four years. Their 
term of office may be renewed once. If, however, their membership of the Management 
Board ends at any time during their term of office, their term of office shall automatically 
expire on that date. 


The detailed procedure for the election of the Chairperson and the Vice-Chairperson 
shall be set out in the rules of procedure of the Management Board. 
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Article 59 
Meetings of the Management Board 
The Chairperson shall convene the meetings of the Management Board. 
The Executive Director shall take part in the deliberations, without the right to vote. 


The Management Board shall hold at least two ordinary meetings a year. In addition, it 
shall meet on the initiative of its Chairperson, at the request of the Commission, or at the 
request of at least one-third of its members. 


The Management Board may invite any person whose opinion may be of interest to attend 
its meetings as an observer, including representatives of the Victims Board. 


The members of the Management Board and their alternates may, subject to its rules of 
procedure, be assisted at the meetings by advisers or experts, including representatives of 
the Victims Board. 


The EU Centre shall provide the secretariat for the Management Board. 
Article 60 
Voting rules of the Management Board 


Unless provided otherwise in this Regulation, the Management Board shall take decisions 
by absolute majority of its members with voting rights. 


Each member shall have one vote. In the absence of a member with the right to vote, his/ 
her alternate shall be entitled to exercise his/her right to vote. 


The Executive Director shall not take part in the voting. 


The Management Board's rules of procedure shall establish more detailed voting 
arrangements, in particular the circumstances in which a member may act on behalf of 
another member. 
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Part 2: Executive Board 


Article 61 
Composition and appointment of the Executive Board 


The Executive Board shall be composed of the Chairperson and the Deputy Chairperson of 
the Management Board, two other members appointed by the Management Board from 
among its members with the right to vote and two representatives of the Commission to the 
Management Board. The Chairperson of the Management Board shall also be the 
Chairperson of the Executive Board. 


The Executive Director shall participate in meetings of the Executive Board without the 
right to vote. 


The term of office of members of the Executive Board shall be four years. In the course of 
the 12 months preceding the end of the four-year term of office of the Chairperson and five 
members of the Executive Board, the Management Board or a smaller committee selected 
among Management Board members including a Commission representative shall carry 
out an assessment of performance of the Executive Board. The assessment shall take into 
account an evaluation of the Executive Board members’ performance and the EU Centre’s 
future tasks and challenges. Based on the assessment, the Management Board may extend 
their term of office once. 


Article 62 
Tasks of the Executive Board 


The Executive Board shall be responsible for the overall planning and the execution of the 
tasks conferred on the EU Centre pursuant to Article 43. The Executive Board shall adopt 
all the decisions of the EU Centre with the exception of the decisions that shall be taken by 
the Management Board in accordance with Article 57. 


In addition, the Executive Board shall have the following tasks: 


(a) adopt, by 30 November of each year, on the basis of a proposal by the Executive 
Director, the draft Single Programming Document, and shall transmit it for 
information to the European Parliament, the Council and the Commission by 31 
January the following year, as well as any other updated version of the document; 


(b) adopt the draft annual budget of the EU Centre and exercise other functions in 
respect of the EU Centre’s budget; 
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(c) 


(d) 


(e) 


(f) 
(g) 


(h) 


(i) 


Gj) 


(k) 


(I) 


assess and adopt a consolidated annual activity report on the EU Centre's activities, 
including an overview of the fulfilment of its tasks and send it, by 1 July each year, 
to the European Parliament, the Council, the Commission and the Court of Auditors 
and make the consolidated annual activity report public; 


adopt an anti-fraud strategy, proportionate to fraud risks taking into account the costs 
and benefits of the measures to be implemented, an efficiency gains and synergies 
strategy, a strategy for cooperation with third countries and/or international 
organisations, and a strategy for the organisational management and internal control 
systems 


adopt rules for the prevention and management of conflicts of interest in respect of 
its members; 


adopt its rules of procedure; 


exercise, with respect to the staff of the EU Centre, the powers conferred by the Staff 
Regulations on the Appointing Authority and by the Conditions of Employment of 
Other Servants on the EU Centre Empowered to Conclude a Contract of 
Employment? ("the appointing authority powers"); 


adopt appropriate implementing rules for giving effect to the Staff Regulations and 
the Conditions of Employment of Other Servants in accordance with Article 110(2) 
of the Staff Regulations; 


appoint the Executive Director and remove him/her from office, in accordance with 
Article 65; 


appoint an Accounting Officer, who may be the Commission's Accounting Officer, 
subject to the Staff Regulations and the Conditions of Employment of other servants, 
who shall be totally independent in the performance of his/her duties; 


ensure adequate follow-up to findings and recommendations stemming from the 
internal or external audit reports and evaluations, as well as from investigations of 
the European Anti-Fraud Office (OLAF); 


adopt the financial rules applicable to the EU Centre; 


46 


Regulation (EEC, Euratom, ECSC) No 259/68 of the Council of 29 February 1968 laying 
down the Staff Regulations of Officials and the Conditions of Employment of Other Servants 
of the European Communities and instituting special measures temporarily applicable to 
officials of the Commission (OJ L 56, 4.3.1968, p. 1) 
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(m) take all decisions on the establishment of the EU Centre's internal structures and, 
where necessary, their modification. 


(n) appoint a Data Protection Officer; 


(0) adopt internal guidelines further specifying the procedures for the processing of 
information in accordance with Article 51, after consulting the European Data 
Protection Supervisor; 


(p) authorise the conclusion of memoranda of understanding referred to in Article 53(3) 
and Article 54(2). 


With respect to the powers mentioned in paragraph 2 point (g) and (h), the Executive 
Board shall adopt, in accordance with Article 110(2) of the Staff Regulations, a decision 
based on Article 2(1) of the Staff Regulations and Article 6 of the Conditions of 
Employment, delegating relevant appointing authority powers to the Executive Director. 
The Executive Director shall be authorised to sub-delegate those powers. 


In exceptional circumstances, the Executive Board may by way of a decision temporarily 
suspend the delegation of the appointing authority powers to the Executive Director and 
any sub-delegation by the latter and exercise them itself or delegate them to one of its 
members or to a staff member other than the Executive Director. 


Where necessary because of urgency, the Executive Board may take certain provisional 
decisions on behalf of the Management Board, in particular on administrative management 
matters, including the suspension of the delegation of the appointing authority powers and 
budgetary matters. 


Article 63 
Voting rules of the Executive Board 


The Executive Board shall take decisions by simple majority of its members. Each member 
of the Executive Board shall have one vote. The Chairperson shall have a casting vote in 
case of a tie. 
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The representatives of the Commission shall have a right to vote whenever matters 
pertaining to Article 62(2), points (a) to (1) and (p) are discussed and decided upon. For the 
purposes of taking the decisions referred to in Article 62(2), points (f) and (g), the 
representatives of the Commission shall have one vote each. The decisions referred to in 
Article 62(2), points (b) to (e), (h) to (1) and (p), may only be taken if the representatives of 
the Commission casts a positive vote. For the purposes of taking the decisions referred to 
in Article 62(2), point (a), the consent of the representatives of the Commission shall only 
be required on the elements of the decision not related to the annual and multi-annual 
working programme of the EU Centre. 


The Executive Board's rules of procedure shall establish more detailed voting 
arrangements, in particular the circumstances in which a member may act on behalf of 
another member. 


Part 3: Executive Director 


Article 64 
Responsibilities of the Executive Director 


The Executive Director shall manage the EU Centre. The Executive Director shall be 
accountable to the Management Board. 


The Executive Director shall report to the European Parliament on the performance of his/ 
her duties when invited to do so. The Council may invite the Executive Director to report 
on the performance of his/her duties. 


The Executive Director shall be the legal representative of the EU Centre. 


The Executive Director shall be responsible for the implementation of the tasks assigned to 
the EU Centre by this Regulation. In particular, the Executive Director shall be responsible 
for: 


(a) the day-to-day administration of the EU Centre; 
(b) preparing decisions to be adopted by the Management Board; 
(c) implementing decisions adopted by the Management Board; 


(d) preparing the Single Programming Document and submitting it to the Executive 
Board after consulting the Commission; 


(e) implementing the Single Programming Document and reporting to the Executive 
Board on its implementation; 
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(f) 


(g) 


(h) 


(i) 


Gj) 
(k) 


(I) 


(m) 


(n) 


(0) 


(p) 


preparing the Consolidated Annual Activity Report (CAAR) on the EU Centre’s 
activities and presenting it to the Executive Board for assessment and adoption; 


preparing an action plan following-up conclusions of internal or external audit 
reports and evaluations, as well as investigations by the European Anti-Fraud Office 
(OLAF) and by the European Public Prosecutor’s Office (EPPO) and reporting on 
progress twice a year to the Commission and regularly to the Management Board and 
the Executive Board; 


protecting the financial interests of the Union by applying preventive measures 
against fraud, corruption and any other illegal activities, without prejudicing the 
investigative competence of OLAF and EPPO by effective checks and, if 
irregularities are detected, by recovering amounts wrongly paid and, where 
appropriate, by imposing effective, proportionate and dissuasive administrative, 
including financial penalties; 


preparing an anti-fraud strategy, an efficiency gains and synergies strategy, a strategy 
for cooperation with third countries and/or international organisations and a strategy 
for the organisational management and internal control systems for the EU Centre 
and presenting them to the Executive Board for approval; 


preparing draft financial rules applicable to the EU Centre; 


preparing the EU Centre’s draft statement of estimates of revenue and expenditure 
and implementing its budget; 


preparing and implementing an IT security strategy, ensuring appropriate risk 
management for all IT infrastructure, systems and services, which are developed or 
procured by the EU Centre as well as sufficient IT security funding. 


implementing the annual work programme of the EU Centre under the control of the 
Executive Board; 


drawing up a draft statement of estimates of the EU Centre’s revenue and 
expenditure as part of the EU Centre’s Single Programming Document and 
implementing the budget of the EU Centre pursuant to Article 67; 


preparing a draft report describing all activities of the EU Centre with a section on 
financial and administrative matters; 


fostering recruitment of appropriately skilled and experienced EU Centre staff, while 
ensuring gender balance. 
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Where exceptional circumstances so require, the Executive Director may decide to locate 
one or more staff in another Member State for the purpose of carrying out the EU Centre’s 
tasks in an a more efficient, effective and coherent manner. Before deciding to establish a 
local office, the Executive Director shall obtain the prior consent of the Commission, the 
Management Board and the Member State concerned. The decision shall be based on an 
appropriate cost-benefit analysis that demonstrates in particular the added value of such 
decision and specify the scope of the activities to be carried out at the local office in a 
manner that avoids unnecessary costs and duplication of administrative functions of the 
EU Centre. A headquarters agreement with the Member State(s) concerned may be 
concluded. 


Without prejudice to the powers of the Commission, of the Management Board 
and of the Executive Board, the Executive Director shall be independent in the 
performance of the duties and shall neither seek nor take instructions from any 
government nor from any other body. 


Article 65 
Executive Director 


The Executive Director shall be engaged as a temporary agent of the EU Centre under 
Article 2(a) of the Conditions of Employment of Other Servants. 


The Executive Director shall be appointed by the Executive Board, from a list of 
candidates proposed by the Commission, following an open and transparent selection 
procedure. 


For the purpose of concluding the contract with the Executive Director, the EU Centre 
shall be represented by the Chairperson of the Executive Board. 


The term of office of the Executive Director shall be five years. Six months before the end 
of the Executive Director’s term of office, the Commission shall complete an assessment 
that takes into account an evaluation of the Executive Director's performance and the EU 
Centre's future tasks and challenges. 


The Executive Board, acting on a proposal from the Commission that takes into account 
the assessment referred to in paragraph 3, may extend the term of office of the Executive 
Director once, for no more than five years. 


An Executive Director whose term of office has been extended may not participate in 
another selection procedure for the same post at the end of the overall period. 
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The Executive Director may be dismissed only upon a decision of the Executive Board 
Lf We ne 

The Executive Board shall take decisions on appointment, extension of the term of office 

or dismissal of the Executive Director by a majority of two-thirds of its members with 

voting rights. 


Subsection 5: Technology Committee 
Article 66 
Establishment and tasks of the Technology Committee 


The Technology Committee shall consist of technical experts appointed by the 
Management Board in view of their excellence and their independence, following the 
publication of a call for expressions of interest in the Official Journal of the European 
Union. 


Procedures concerning the appointment of the members of the Technology Committee and 
its operation shall be specified in the rules of procedure of the Management Board and 
shall be made public. 


The members of the Committee shall be independent in carrying out their tasks as 
members of the Committee and shall act in the public interest. The list of members of the 
Committee shall be made public and shall be updated by the EU Centre on its website. 


When a member no longer meets the criteria of independence, he or she shall inform the 
Management Board. Alternatively, the Management Board may declare, on a proposal of at 
least one third of its members or of the Commission, a lack of independence and revoke 
the person concerned. The Management Board shall appoint a new member for the 
remaining term of office in accordance with the procedure for ordinary members. 


The mandates of members of the Technology Committee shall be four years. Those 
mandates shall be renewable once. 


The Technology Committee shall 


(a) contribute to the EU Centre’s opinions referred to in Article 7(3), first subparagraph, 
point (d); 


(b) contribute to the EU Centre’s assistance to the Coordinating Authorities, the 
Management Board, the Executive Board and the Executive Director, in respect of 
matters related to the use of technology; 


(c) provide internally, upon request, expertise on matters related to the use of technology 
for the purposes of prevention and detection of child sexual abuse online. 
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Article 66a 
Appointment and tasks of the Victims and-Survivers Board 


The Victims and-Survivers Board shall be comprised of adult victims and-survivers of 
child sexual abuse and recognised experts in providing assistance to victims who, 
following a call for expressions of interest published in the Official Journal of the 
European Union, will be appointed by the Management Board on the basis of their 
personal experience, expertise and independence. 


The procedures governing the appointment of the members of the Victims and 
Survivers Board, its functioning and the conditions governing the transmission of 
information to the Victims and-Survivers Board shall be laid down in the 
Management Board’s Rules of Procedure, and shall be published. 


The members of the Victims and-Survivers Board shall be independent in carrying 
out their tasks as members of the Board and shall act in the interest of persons 
affected by online child sexual abuse. The EU Centre shall publish on its website and 
keep up to date the list of the members of the Victims and-Survivers Board. 


Members who cease to be independent shall inform the Management Board 
accordingly. Otherwise, the Management Board, at the proposal of at least one third 
of its members or of the Commission, may determine that they lack sufficient 
independence and revoke their appointment. The Management Board shall appoint 
new members to replace them for the remainder of their predecessors’ term of office, 
following the same procedure as the one governing ordinary members. 


The term of office of members of the Victims and-Survivers Board shall be four 
years. It may be renewed once. 


The Executive Director and the Management Board may consult the Victims and 
Survivers Board in connection with all matters concerning persons affected by online 
child sexual abuse. 


The Victims and Survivers Board has the following tasks: 
(a) make the concerns of victims survivers visible; 


(b) advise the Management Board in matters referred to in Article 57 (1)(fa), 
sentence2; 


(c) advise the Executive Director and the Management Board as foreseen in 
paragraph 6; 
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(d) incorporate their experience and expertise as regards preventing and combating 
online child sexual abuse, assisting and supporting victims survivers 


(e) contribute own proposals for the work of the competent authorities; 


(f) contribute to the European networking of victims and-survivers of child sexual 
abuse. 


Section 6 
Establishment and Structure of the Budget 
Subsection 1 
Single Programming Document 
Article 67 
Budget establishment and implementation 


Each year the Executive Director shall draw up a draft statement of estimates of the EU 
Centre’s revenue and expenditure for the following financial year, corresponding to the 
calendar year, including an establishment plan, and shall send it to the Executive Board. 


The Executive Board shall, on the basis of the draft statement of estimates, adopt a 
provisional draft estimate of the EU Centre’s revenue and expenditure for the following 
financial year and shall send it to the Commission by 31 January each year. 


The Executive Board shall send the final draft estimate of the EU Centre’s revenue and 
expenditure, which shall include a draft establishment plan, to the European Parliament, 
the Council and the Commission by 31 March each year. 


The Commission shall send the statement of estimates to the European Parliament and the 
Council, together with the draft general budget of the Union. 


On the basis of the statement of estimates, the Commission shall enter in the draft general 
budget of the Union the estimates that it considers necessary for the establishment plan and 
the amount of the contribution to be charged to the general budget, which it shall place 
before the European Parliament and the Council in accordance with Articles 313 and 314 
of the Treaty on the Functioning of the European Union. 


The European Parliament and the Council shall authorise the appropriations for the 
contribution from the Union to the EU Centre. 


The European Parliament and the Council shall adopt the EU Centre’s establishment plan. 
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10. 


The EU Centre’s budget shall be adopted by the Executive Board. It shall become final 
following the final adoption of the general budget of the Union. Where necessary, it shall 
be adjusted accordingly. 


The Executive Director shall implement the EU Centre’s budget. 


Each year the Executive Director shall send to the European Parliament and the Council all 
information relevant to the findings of any evaluation procedures. 


Article 68 


Financial rules 


The financial rules applicable to the EU Centre shall be adopted by the Executive Board after 
consultation with the Commission. They shall not depart from Delegated Regulation (EU) 
2019/71547 unless such a departure is specifically required for the operation of the EU Centre and 
the Commission has given its prior consent. 


Subsection 2 
Presentation, implementation and control of the budget 
Article 69 
Budget 


Estimates of all revenue and expenditure for the EU Centre shall be prepared each 
financial year, which shall correspond to the calendar year, and shall be shown in the EU 
Centre’s budget, which shall be balanced in terms of revenue and of expenditure. 


Without prejudice to other resources, the EU Centre’s revenue shall comprise a 
contribution from the Union entered in the general budget of the Union. 


The EU Centre may benefit from Union funding in the form of delegation agreements or 
ad hoc grants in accordance with its financial rules referred to in Article 68 and with the 
provisions of the relevant instruments supporting the policies of the Union. 


The EU Centre’s expenditure shall include staff remuneration, administrative and 
infrastructure expenses, and operating costs. 


Budgetary commitments for actions relating to large-scale projects extending over more 
than one financial year may be broken down into several annual instalments. 


47 


OJ L 122, 10.5.2019, p. 1. 
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Article 70 
Presentation of accounts and discharge 


The EU Centre’s accounting officer shall send the provisional accounts for the financial 
year (year N) to the Commission's accounting officer and to the Court of Auditors by 1 
March of the following financial year (year N + 1). 


The EU Centre shall send a report on the budgetary and financial management for year N 
to the European Parliament, the Council and the Court of Auditors by 31 March of year N 
+ 1, 


The Commission's accounting officer shall send the EU Centre’s provisional accounts for 
year N, consolidated with the Commission's accounts, to the Court of Auditors by 31 
March of year N + 1. 


The Management Board shall deliver an opinion on the EU Centre’s final accounts for year 
N. 


The EU Centre’s accounting officer shall, by 1 July of year N + 1, send the final accounts 
for year N to the European Parliament, the Council, the Commission, the Court of Auditors 
and national parliaments, together with the Management Board's opinion. 


The final accounts for year N shall be published in the Official Journal of the European 
Union by 15 November of year N + 1. 


The Executive Director shall send to the Court of Auditors, by 30 September of year N + 1, 
a reply to the observations made in its annual report. He or she shall also send the reply to 
the Management Board. 


The Executive Director shall submit to the European Parliament, at the latter's request, any 
information required for the smooth application of the discharge procedure for year N. 


On a recommendation from the Council acting by a qualified majority, the European 
Parliament shall, before 15 May of year N + 2, grant a discharge to the Executive Director 
in respect of the implementation of the budget for year N. 
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Section 7 
Staff 
Article 71 
General provisions 


lL, The Staff Regulations and the Conditions of Employment of Other Servants and the rules 
adopted by agreement between the institutions of the Union for giving effect thereto shall 
apply to the EU Centre for all matters not covered by this Regulation. 


2. The Executive Board, in agreement with the Commission, shall adopt the necessary 
implementing measures, in accordance with the arrangements provided for in Article 110 
of the Staff Regulations. 


3. The EU Centre staff, in particular those working in areas related to detection, reporting and 
removal of online child sexual abuse, shall have access to appropriate counselling and 
support services. 


Article 72 
Seconded national experts and other staff 


1. The EU Centre may make use of seconded national experts or other staff not employed by 
it. 

2: The Executive Board shall adopt rules related to staff from Member States, including the 
contact officers referred to in Article 52, to be seconded to the EU Centre and update them 
as necessary. Those rules shall include, in particular, the financial arrangements related to 
those secondments, including insurance and training. Those rules shall take into account 
the fact that the staff is seconded and to be deployed as staff of the EU Centre. They shall 
include provisions on the conditions of deployment. Where relevant, the Executive Board 
shall aim to ensure consistency with the rules applicable to reimbursement of the mission 
expenses of the statutory staff. 


Article 73 
Privileges and immunities 


Protocol No 7 on the Privileges and Immunities of the European Union annexed to the Treaty on the 
Functioning of the European Union shall apply to the EU Centre and its staff. 


Privileges and immunities of contact officers and members of their families shall be subject to an 
agreement between the Member State where the seat of the EU Centre is located and the other 
Member States. That agreement shall provide for such privileges and immunities as are necessary 
for the proper performance of the tasks of contact officers. 
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Article 74 
Obligation of professional secrecy 


Members of the Management Board and the Executive Board, and all members of the staff 
of the EU Centre, including officials seconded by Member States on a temporary basis, and 
all other persons carrying out tasks for the EU Centre on a contractual basis, shall be 
subject to the requirements of professional secrecy pursuant to Article 339 of the Treaty on 
the Functioning of the European Union even after their duties have ceased. 


The Executive Board shall ensure that individuals who provide any service, directly or 
indirectly, permanently or occasionally, relating to the tasks of the EU Centre, including 
officials and other persons authorised by the Executive Board or appointed by the 
coordinating authorities for that purpose, are subject to requirements of professional 
secrecy equivalent to those in paragraph 1. 


The EU Centre shall establish practical arrangements for implementing the confidentiality 
rules referred to in paragraphs 1 and 2. 


The EU Centre shall apply Commission Decision (EU, Euratom) 2015/44448, 
Article 75 
Security rules on the protection of classified and sensitive non-classified information 


The EU Centre shall adopt its own security rules equivalent to the Commission’s security 
rules for protecting European Union Classified Information (EUCI) and sensitive non- 
classified information, as set out in Commission Decisions (EU, Euratom) 2015/44349 and 
(EU, Euratom) 2015/444. The security rules of the EU Centre shall cover, inter alia, 
provisions for the exchange, processing and storage of such information. The Executive 
Board shall adopt the EU Centre’s security rules following approval by the Commission. 


Any administrative arrangement on the exchange of classified information with the 
relevant authorities of a third country or, in the absence of such arrangement, any 
exceptional ad-hoc release of EUCI to those authorities, shall be subject to the 
Commission’s prior approval. 


Commission Decision (EU, Euratom) 2015/444 of 13 March 2015 on the security rules for 
protecting EU classified information (OJ L 72, 17.3.2015, p. 53). 


Commission Decision (EU, Euratom) 2015/443 of 13 March 2015 on Security in the 
Commission (OJ L 72, 17.3.2015, p. 41). 
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Section 8 
General provisions 
Article 76 


Language arrangements 


The provisions laid down in Regulation No 15% shall apply to the EU Centre. The translation 
services required for the functioning of the EU Centre shall be provided by the Translation Centre 
for the bodies of the European Union. 


Article 77 
Transparency and communication 


Regulation (EC) No 1049/20015! shall apply to documents held by the EU Centre. The 
Management Board shall, within six months of the date of its first meeting, adopt the 
detailed rules for applying that Regulation. 


The processing of personal data by the EU Centre shall be subject to Regulation (EU) 
2018/1725. The Management Board shall, within six months of the date of its first 
meeting, establish measures for the application of that Regulation by the EU Centre, 
including those concerning the appointment of a Data Protection Officer of the EU Centre. 
Those measures shall be established after consultation of the European Data Protection 
Supervisor. 


The EU Centre may engage in communication activities on its own initiative within its 
field of competence. Communication activities shall be carried out in accordance with 
relevant communication and dissemination plans adopted by the Management Board. 


Article 78 
Anti-fraud measures 


In order to combat fraud, corruption and other unlawful activities, Regulation (EU, 
Euratom) No 883/201352 shall apply. 


50 


51 


52 


Regulation No | determining the languages to be used by the European Economic 
Community (OJ 17, 6.10.1958, p. 385/58). 


Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 
2001 regarding public access to European Parliament, Council and Commission documents, 
Official Journal L 145 , 31/05/2001 P. 0043 — 0048. 


Regulation (EU, Euratom) No 883/2013 of the European Parliament and of the Council of 11 
September 2013 concerning investigations conducted by the European Anti-Fraud Office 
(OLAF) and repealing Regulation (EC) No 1073/1999 of the European Parliament and of the 
Council and Council Regulation (Euratom) No 1074/1999. (OJ L 248, 18.9.2013, p. 1). 
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The EU Centre shall accede to the Interinstitutional Agreement of 25 May 1999 between 
the European Parliament, the Council of the European Union and the Commission of the 
European Communities concerning internal investigations by OLAF within six months 
from [date of start of operations as set out in Article 82| and shall adopt the appropriate 
provisions applicable to its staff using the template set out in the Annex to that Agreement. 


The European Court of Auditors shall have the power of audit, on the basis of documents 
and on the spot, over all grant beneficiaries, contractors and subcontractors who have 
received Union funds from the EU Centre. 


OLAF may carry out investigations, including on-the-spot checks and inspections with a 
view to establishing whether there has been fraud, corruption or any other illegal activity 
affecting the financial interests of the Union in connection with a grant or a contract 
funded by the EU Centre, in accordance with the provisions and procedures laid down in 
Regulation (EU, Euratom) No 883/2013 and Council Regulation (Euratom, EC) No 
2185/9653. 


Without prejudice to paragraphs 1, 2, 3, and 4, cooperation agreements with third countries 
and international organisations, contracts, grant agreements and grant decisions of the EU 
Centre shall contain provisions expressly empowering the European Court of Auditors and 
OLAF to conduct such audits and investigations, i accordance with their respective 
competences. 


Article 79 

Liability 
The EU Centre's contractual liability shall be governed by the law applicable to the 
contract in question. 


The Court of Justice of the European Union shall have jurisdiction to give judgment 
pursuant to any arbitration clause contained in a contract concluded by the EU Centre. 


In the case of non-contractual liability, the EU Centre shall, in accordance with the general 
principles common to the laws of the Member States, make good any damage caused by its 
departments or by its staff in the performance of their duties. 


The Court of Justice of the European Union shall have jurisdiction in disputes over 
compensation for damages referred to in paragraph 3. 


The personal liability of its staff towards the Centre shall be governed by the provisions 
laid down in the Staff Regulations or Conditions of Employment applicable to them. 


53 


Council Regulation (Euratom, EC) No 2185/96 of 11 November 1996 concerning on-the-spot 
checks and inspections carried out by the Commission in order to protect the European 
Communities’ financial interests against fraud and other irregularities. (OJ L 292, 15.11.1996, 


p. 2). 
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Article 80 
Administrative inquiries 


The activities of the EU Centre shall be subject to the inquiries of the European Ombudsman in 
accordance with Article 228 of the Treaty on the Functioning of the European Union. 


Article 81 
Headquarters Agreement and operating conditions 


iE The necessary arrangements concerning the accommodation to be provided for the EU 
Centre in the Member State where the seat of the EU Centre is located and the facilities to 
be made available by that Member State, together with the specific rules applicable in that 
Member State to the Executive Director, members of the Executive Board, EU Centre staff 
and members of their families shall be laid down in a Headquarters Agreement between the 
EU Centre and the Member State where the seat of the EU Centre is located, concluded 
after obtaining the approval of the Executive Board and no later than /2 years after the 
entry into force of this Regulation]. 


2. The Member State where the seat of the EU Centre is located shall provide the best 
possible conditions to ensure the smooth and efficient functioning of the EU Centre, 
including multilingual, European-oriented schooling and appropriate transport connections. 


Article 82 
Start of the EU Centre's activities 


dl The Commission shall be responsible for the establishment and initial operation of the EU 
Centre until the Executive Director has taken up his or her duties following his or her 
appointment by the Executive Board in accordance with Article 65(2). For that purpose: 


(a) the Commission may designate a Commission official to act as interim Executive 
Director and exercise the duties assigned to the Executive Director; 


(b) by derogation from Article 62(2)(g) and until the adoption of a decision as referred to 
in Article 62(4), the interim Executive Director shall exercise the appointing 
authority power; 


(c) the Commission may offer assistance to the EU Centre, in particular by seconding 
Commission officials to carry out the activities of the EU Centre under the 
responsibility of the interim Executive Director or the Executive Director; 


(d) the interim Executive Director may authorise all payments covered by appropriations 
entered in the EU Centre's budget after approval by the Executive Board and may 
conclude contracts, including staff contracts, following the adoption of the EU 
Centre's establishment plan. 
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CHAPTER V 


DATA COLLECTION AND TRANSPARENCY REPORTING 
Article 83 
Data collection 


Providers of relevant information society services that were subject to orders under 
Articles 7, 14, 14a, 16 and 18a -Previders-of hosting services, previders_ofinterpersonal 
conmunications_services, _providers_of internet aceess_services shall collect data on the 
following topics and make that information available to the EU Centre upon request: 


(a) where the provider has been subject to a detection order issued in accordance with 
Article 7: 


- the measures taken to comply with the order, including the technologies used 
for that purpose and the safeguards provided; 


- the error rates of the technologies deployed to detect online child sexual abuse 
and measures taken to prevent or remedy any errors; 


- in relation to complaints and cases submitted by users in connection to the 
measures taken to comply with the order, the number of complaints submitted 
directly to the provider, the number of cases brought before a judicial authority, 
the basis for those complaints and cases, the decisions taken in respect of those 
complaints and in those cases, the average time needed for taking those 
decisions and the number of instances where those decisions were 
subsequently reversed; 


(b) the number of removal orders and cross-border removal orders issued to the 
provider in accordance with Articles 14 and 14a—the-average—time—needed_—for 


(c) the total number of items of child sexual abuse material that the provider removed or 
to which it disabled access, broken down by whether the items were removed or 
access thereto was disabled pursuant to a removal order, cross-border removal 
order or to a notice submitted by a Competent Authority, the EU Centre or a third 
party or at the provider’s own initiative; 


(d) the number of blocking orders issued to the provider in accordance with Article 16; 


(da) the number of delisting orders issued to the provider in accordance with Article 
18a; 
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(e) the number of instances in which the provider invoked Article 8(3), Article 14(5) or 
(6), et Article 17(4a) or (5) or Article 18b(4) or (5), together with the reasons 


grounds therefor; 


Relying to the extent possible on information collected in an automated manner by 
means of the secure information system or systems referred to in Article 39(2a), [as 


well as on any similar system that might be used for the exchange of information at 
national level,| the Coordinating Authorities shall collect data on the following topics and 


make that information available to the EU Centre upon request*4: 


(a) the follow-up given to reports of potential online child sexual abuse that the EU 
Centre forwarded in accordance with Article 48(3), specifying for each report: 


- whether the report led to the launch of a criminal investigation or contributed 
to an ongoing investigation, ted te taking any other action ledte ne-action: 


— where no action was taken, the reasons for not taking any action: 


(b) the most important and recurrent risks of online child sexual abuse, as reported by 
providers of hosting services and providers of interpersonal communications services 
in accordance with Article 53 or identified through other information available te+he 
Ha aediank Lege: 

(c) a list of the providers of hosting services and providers of interpersonal 
communications services to which the Coordinating Authority addressed a detection 
order in accordance with Article 7; 


54 


55 


PCY comment: While concluding that many delegations have objections to the level of detail 
in this provision and the inclusion of investigative information, the LEWP could reflect on 
developing the data collection from Coordinating Authorities on the basis of a delegated act, 
as in Article 84(6), and in combination with the IT system as provided for in Article 39 that 
will enable the swift collection of statistics. 


PCY comment: COM suggests reinstating this text, in coherence with the existing obligations 
under Article 8 of the Interim Regulation: “whether victims were identified and rescued 
and if so their numbers differentiating by gender and age, and whether any suspects 
were arrested and any perpetrators were convicted and if so their numbers”. 
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(d) 


(e) 


(f) 


(g) 


the number of detection orders issued in accordance with Article 7, broken down by 
provider and by type of online child sexual abuse, and the number of instances in 
which the provider invoked Article 8(3); 


a list of providers of hosting services to which the-Coordinating Authorityissued a 
removal order or cross-border removal order were issued in accordance with 
Articles 14 and 14a; 


the number of removal orders issued in accordance with Article 14, broken down by 
provider, the tone needed to remove_or disable access tothe item oritems_of child 
sexualabusematerial concerned, and the number of instances in which the provider 
invoked Article 14(5) and (6); 


the number of blocking orders issued in accordance with Article 16, broken down by 
provider, and the number of instances in which the provider invoked Article 17(4a) 
or (5); 


(ga) the number of complaints received in accordance with Article 34 broken down 


by what the alleged infringement of this Regulation was concerned with and 


3. The EU Centre shall collect data and generate statistics on the detection, reporting, 
removal of or disabling of access to online child sexual abuse under this Regulation. The 
data shall be in particular on the following topics:56 


(a) 


(b) 


the number of indicators in the databases of indicators referred to in Article 44 and 
the development of that number as compared to previous years; 


the number of submissions of child sexual abuse material and solicitation of children 
referred to in Article 36(1), broken down by Member State that designated the 
submitting Coordinating Authorities, and, in the case of child sexual abuse material, 
the number of indicators generated on the basis thereof and the number of uniform 
resource locators included in the list of uniform resource locators in accordance with 
Article 44(3); 


56 PCY comment: It seems to the PCY that several items in paragraph 3 can only be properly 
assessed and discussed once increased clarity on the outcome of their respective basis is 


reached. 
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(c) the total number of reports submitted to the EU Centre in accordance with Article 12, 
broken down by provider of hosting services and provider of interpersonal 
communications services that submitted the report and by Member State the 
competent authority of which the EU Centre forwarded the reports to in accordance 
with Article 48(3); 


(d) the enline-child sexual abuse te—which the reports relate includine the_number of 
items of potential known and new child sexual abuse material and instances of 
potential solicitation of children included in the reports the-Member—Statethe 
competent autherity_ofwhich the EU Centre forwarded the -reperts te in accordance 
with Article 48(3), and type of relevant information society service that the reporting 
provider offers; 


(e) the number of reports that the EU Centre considered manifestly. unfounded, as 
referred to in Article 48(2); 


(f) the number of reports relating to potential new child sexual abuse material and 
solicitation of children that were assessed as not constituting child sexual abuse 
material of which the EU Centre was informed pursuant to Article 36(3), broken 
down by Member State; 


(g) the results of the searches in accordance with Article 49(1), including the number of 
images, videos and URLs by Member State where the material is hosted; 


(h) where the same item of potential child sexual abuse material was reported more than 
once to the EU Centre in accordance with Article 12 or detected more than once 
through the searches in accordance with Article 49(1), the number of times that that 
item was reported or detected in that manner. 


(i) the number of notices and number of providers of hosting services notified by the EU 
Centre pursuant to Article 49(2); 


(j) number of victims of online child sexual abuse assisted by the EU Centre pursuant to 
Article 21(2), and the number of these victims that requested to receive such 
assistance in a manner accessible to them due to disabilities. 


Providers of relevant information society services that were subject to orders under 
Articles 7, 14, 14a, 16 and 18a W—Phe—providers—of_hestine services,_previders—of 
seeaane ip, “CREAN ror ee reaper am ter rete eo nia res seaese- thie 
Coordinating Authorities [or other competent authorities] and the EU Centre shall ensure 
that the data referred to in paragraphs 1, 2 and 3, respectively, is stored no longer than is 
necessary for the transparency reporting referred to in Article 84. The data stered referred 
to in paragraphs 1 to 3 shall not contain any personal data. 
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5. They shall ensure that the data is stored in a secure manner and that the storage is subject 
to appropriate technical and organisational safeguards. Those safeguards shall ensure, in 
particular, that the data can be accessed and processed only for the purpose for which it is 
stored, that a high level of security is achieved and that the information is deleted when no 
longer necessary for that purpose. They shall regularly review those safeguards and adjust 
them where necessary. 


6. The Commission shall be empowered to adopt delegated acts in accordance with 
Article 86 in order to supplement this Regulation with the necessary detailed rules 
concerning the process of data collection and categorisation of the data to be collected 
pursuant to paragraphs 1 to 4 for the purposes of follow up of the reports and the 
application of the Regulation. 


Article 84 
Transparency reporting 


1. Each provider of relevant information society services that were subject to orders under 
Articles 7, 14, 14a, 16 and 18a during the relevant year shall draw up an annual report 
on its activities under this Regulation. That report shall compile the information referred to 
in Article 83(1). The providers shall, by 31 January of every year subsequent to the year to 
which the report relates, make the report available to the public and communicate it to the 
Coordinating Authority of establishment, the Commission and the EU Centre. 


2. Each Coordinating Authority shall draw up an annual report on its activities under this 
Regulation. That report shall compile the information referred to in Article 83(2). It shall, 
by 31 March of every year subsequent to the year to which the report relates, make the 
report available to the public and communicate it to the Commission and the EU Centre. 


3% Where a Member State has designated several competent authorities pursuant to Article 25, 
it shall ensure that the Coordinating Authority draws up a single report covering the 
activities of all competent authorities under this Regulation and that the Coordinating 
Authority receives all relevant information and support needed to that effect from the other 
competent authorities concerned. 


4. The EU Centre ee 2 s atine Ay shall draw 
up an annual report on its activities under this Regulation. That report shall alse compile 
and analyse the information contained in the reports referred to in paragraphs 2 and Article 
83(3). The EU Centre shall, by 30 June of every year subsequent to the year to which the 
report relates, make the report available to the public and communicate it to the 
Commission. 


5. The annual transparency reports referred to in paragraphs 1, 2 and 3 shall not include any 
information that may prejudice ongoing activities for the assistance to victims or the 
prevention, detection, investigation or prosecution of child sexual abuse offences. They 
shall alse-not contain any personal data. 


6. The Commission shall be empowered to adopt delegated acts in accordance with Article 86 
in order to supplement this Regulation with the necessary templates and detailed rules 
concerning the form, precise content and other details of the reports and the reporting 
process pursuant to paragraphs 1, 2 and 3. 
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CHAPTER VI 


FINAL PROVISIONS 
Article 85 
Evaluation 


By [five years after the entry into force of this Regulation], and every five years thereafter, 
the Commission shall evaluate this Regulation and submit a report on its application to the 
European Parliament and the Council. 


By [five years after the entry into force of this Regulation], and every five years thereafter, 
the Commission shall ensure that an evaluation in accordance with Commission guidelines 
of the EU Centre’s performance in relation to its objectives, mandate, tasks and governance 
and location is carried out. The evaluation shall, in particular, address the possible need to 
modify the tasks of the EU Centre, and the financial implications of any such modification. 


On the occasion of every second evaluation referred to in paragraph 2, the results achieved 
by the EU Centre shall be assessed by the Commission, having regard to its objectives 
and tasks, including an assessment of whether the continuation of the EU Centre is still 
justified with regard to those objectives and tasks. 


The Commission shall report to the European Parliament and the Council the findings of 
the evaluation referred to in paragraph 3. The findings of the evaluation shall be made 
public. 


For the purpose of carrying out the evaluations referred to in paragraphs 1, 2 and 3, the 
Coordinating Authorities and Member States and the EU Centre shall provide information 
to the Commission at its request. 


In carrying out the evaluations referred to in paragraphs 1, 2 and 3, the Commission shall 
take into account the relevant evidence at its disposal. 


Where appropriate, the reports referred to in paragraphs 1 and 4 shall be accompanied by 
legislative proposals. 
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Article 86 
Exercise of the delegation 


The power to adopt delegated acts is conferred on the Commission subject to the 
conditions laid down in this Article. 


The power to adopt delegated acts referred to in Articles 3, 8, 13, 14, 17, 47 and 84 shall be 
conferred on the Commission for an indeterminate period of time from [date of adoption of 
the Regulation] 5’. 


The delegation of power referred to in Articles 3, 8, 13, 14, 17, 47 and 84 may be revoked 
at any time by the European Parliament or by the Council. A decision to revoke shall put 
an end to the delegation of the power specified in that decision. It shall take effect the day 
after the publication of the decision in the Official Journal of the European Union or at a 
later date specified therein. It shall not affect the validity of any delegated acts already in 
force. 


Before adopting a delegated act, the Commission shall consult experts designated by each 
Member State in accordance with the principles laid down in the Inter-institutional 
Agreement of 13 April 2016 on Better Law-Making. 


As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the 
European Parliament and to the Council. 


A delegated act adopted pursuant to Articles 3, 8, 13, 14, 17, 47 and 84 shall enter into 
force only if no objection has been expressed either by the European Parliament or the 
Council within a period of two months of notification of that act to the European 
Parliament and the Council or if, before the expiry of that period, the European Parliament 
and the Council have both informed the Commission that they will not object. That period 
shall be extended by two months at the initiative of the European Parliament or of the 
Council. 


57 


PCY comment: The PCY has taken note of the comment from some delegations that the 
delegation in relation to Article 47 is concerned with subject-matters that may not be 
appropriate for such delegation due to its principal nature. The PCY suggests that this 
particular issue is discussed in connection with Article 47 and, where needed, in connection 
with the other Articles referred to here. 
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Article 87 
Committee procedure 


ie For the purposes of the adoption of the implementing acts referred to in Article 39(4), the 
Commission shall be assisted by a committee. That committee shall be a committee within 
the meaning of Regulation (EU) No 182/2011. 


2. Where reference is made to this paragraph, Article 4 of Regulation (EU) No 182/2011 shall 
apply. 
Article 8858 
Repeal 


Regulation (EU) 2021/1232 is repealed from [date of application of this Regulation]. 
Article 89 


Entry into force and application 


This Regulation shall enter into force on the twentieth day following that of its publication in the 
Official Journal of the European Union. 


It shall apply from 18 6-months after its entry into force. 


This Regulation shall be binding in its entirety and directly applicable in all Member States. 


Done at Brussels, 
For the European Parliament For the Council 


The President The President 


58 = PCY comment: Many delegations are in favour of exploring how the Temporary Regulation 
could be prolonged and/or how to allow voluntary detection on a permanent basis by 
including the provisions of the Temporary Regulation in this Regulation. 
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ANNEX 


Article 27 [clean version of former Art 27-30] 


Investigatory and enforcement powers 


Where needed in order to carrying out their tasks under this Regulation, competent 
authorities shall have the following powers of investigation, in respect of conduct by 
providers of relevant information society services falling within the competence of their 
Member State: 


(a) 


(b) 


(c) 


(d) 


the power to require those providers, as well as any other persons acting for purposes 
related to their trade, business, craft or profession that may reasonably be aware of 
information relating to a suspected infringement of this Regulation, to provide such 
information without undue delay; 


the power to carry out, or to request a judicial authority to order, inspections of any 
premises that those providers or those persons use for purposes related to their trade, 
business, craft or profession, or to request other public authorities to do so, in order 
to examine, seize, take or obtain copies of information relating to a suspected 
infringement in any form, irrespective of the storage medium; 


the power to ask any member of staff or representative of those providers or those 
persons to give explanations in respect of any information relating to a suspected 
infringement and to record the answers by any technical means; 


the power to request information, including to assess whether the measures taken to 
execute a detection order, removal order, blocking order or delisting order comply 
with the requirements of this Regulation. 


Where needed for carrying out their tasks under this Regulation, competent authorities 
shall have the following enforcement powers, in respect of providers of relevant 
information society services falling within the competence of their Member State: 


(a) 


(b) 


(c) 


the power to accept the commitments offered by those providers in relation to their 
compliance with this Regulation and to make those commitments binding; 


the power to order the cessation of infringements and, where appropriate, to impose 
remedies proportionate to the infringement and necessary to bring the infringement 
effectively to an end or to request a judicial authority to do so; 


the power to impose fines, or request a judicial authority in their Member State to do 
so, in accordance with Article 35 for failure to comply with this Regulation, 
including any of the investigative orders issued pursuant to paragraph 1 of this 
Article; 
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(d) the power to impose a periodic penalty payment, or to request a judicial authority to 
do so, in accordance with Article 35 to ensure that an infringement is terminated in 
compliance with an order issued pursuant to point (b) of this subparagraph or for 
failure to comply with any of the orders issued pursuant to paragraph 1 of this 
Article. 


(e) the power to adopt interim measures or to request the competent national judicial 
authority to do so, to avoid the risk of serious harm. 


As regards the first subparagraph, points (c) and (d), competent authorities shall also have 
the enforcement powers set out in those points in respect of the other persons referred to in 
paragraph 1, for failure to comply with any of the orders issued to them pursuant to that 
paragraph. They shall only exercise those enforcement powers after having provided those 
other persons in good time with all relevant information relating to such orders, including 
the applicable period, the fines or periodic payments that may be imposed for failure to 
comply and the possibilities for redress. 


Where needed for carrying out their tasks under this Regulation, competent authorities 
shall, in respect of providers of relevant information society services falling within the 
competence of their Member State, where all other powers pursuant to this Article to bring 
about the cessation of an infringement have been exhausted and the infringement has not 
been remedied or is continuing and is eausing serious harm which cannot be avoided 
through the exercise of other powers available under Union or national law, also have the 
power to take the following measures: 


(a) to require the management body of the providers, without undue delay, to examine 
the situation, to adopt and submit an action plan setting out the necessary measures 
to terminate the infringement, to ensure that the provider takes those measures, and 
to report on the measures taken; 


(b) where the competent authorities, including the Coordinating Authorities consider that 
a provider of relevant information society services has not sufficiently complied with 
the requirements of point (a), that the infringement has not been remedied or is 
continuing and is causing serious harm, and that that infringement entails a criminal 
offence involving a threat to the life or safety of persons or the infringement results 
in the regular and structural facilitation of child sexual abuse offences, to request that 
the competent judicial authority or other independent administrative authority of its 
Member State order the temporary restriction of access of users of the service 
concermed by the infringement or, only where that is not technically feasible, to the 
online interface of the provider on which the infringement takes place. 


The competent authorities, including the Coordinating Authorities, shall, prior to 
submitting the request referred to in this paragraph, point (b), invite interested parties to 
submit written observations within a period that shall not be less than two weeks, 
describing the measures that it intends to request and identifying the intended addressee or 
addressees thereof. The provider, the intended addressee or addressees and any other third 
party demonstrating a legitimate interest shall be entitled to participate in the proceedings 
before the competent judicial authority or other independent administrative authority. 
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Any measure ordered shall be proportionate to the nature, gravity, recurrence and duration 
of the infringement, without unduly restricting access to lawful information by users of the 
service concerned. 


The restriction of access shall be for a period of four weeks, subject to the possibility for 
the competent judicial authority or other independent administrative authority of the 
Member State, in its order, to allow the competent authorities to extend that period for 
further periods of the same lengths, subject to a maximum number of extensions set by a 
that judicial authority or other independent administrative authority. 


The competent authorities referred to in the previous subparagraph shall only extend the 
period where, having regard to the rights and interests of all parties affected by that 
restriction and all relevant circumstances, including any information that the provider, the 
addressee or addressees and any other third party that demonstrated a legitimate interest 
may provide to it, it considers that both of the following conditions have been met: 


(a) the provider has failed to take the necessary measures to terminate the infringement; 


(b) the temporary restriction does not unduly restrict access to lawful information by 
users of the service, having regard to the number of users affected and whether any 
adequate and readily accessible alternatives exist. 


Where the competent authority considers that the conditions set out in the fourth 
subparagraph, points (a) and (b) have been met but it cannot further extend the period 
pursuant to the fourth subparagraph, it shall submit a new request to the competent judicial 
authority or other independent administrative authority, as referred to in the first 
subparagraph, point (b). 


The measures taken by the competent authorities, including the Coordinating Authorities, 
in the exercise of their powers listed in paragraphs 1, 2 and 3 shall be effective, dissuasive 
and proportionate, having regard, in particular, to the nature, gravity, recurrence and 
duration of the infringement or suspected infringement to which those measures relate, as 
well as the economic, technical and operational capacity of the provider of relevant 
information society services concerned, where relevant. 


Member States shall lay down specific rules and procedures for the exercise of the powers 
pursuant to paragraphs 1, 2 and 3 and shall ensure that any exercise of those powers is 
subject to adequate safeguards laid down in the applicable national law in compliance with 
the Charter and with the general principles of Union law. In particular, those measures 
shall only be taken in accordance with the right to respect for private life and the rights of 
defence, including the rights to be heard and of access to the file, and subject to the right to 
an effective judicial remedy of all affected parties. 
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ANNEX 


Following the new governance model concerning Coordinating Authorities and competent 
authorities, tasks can now be attributed to any competent authority, unless it is specified that they 
should be reserved for Coordinating Authorities. 


Coordinating Authorities are competent authorities acting as contact points and coordinating bodies 
at national and EU level. 


Coordination at national level entails the centralisation of information concerning the 


implementation of the regulation, and the handling of complaints on its infringement. In particular, 
the following tasks are reserved for Coordinating Authorities: 


12) 


Receiving copies of all final removal, blocking orders and delisting orders issued by 
competent authorities in their Member State of establishment; 


Handling complaints for infringements of the Regulation under Article 34; 


Receiving transeripts extracts of written conversations and items of materials identified 
as constituting online CSA by competent authorities in their Member State of 
establishment in accordance with Article 36; 


Transmitting copies of cross-border removal orders received from other Member States 
to the competent authority in their Member State of establishment, if needed; 


Collecting the information referred to in Article 83(2) in relation to their Member State 
of establishment, with the cooperation of all national competent authorities; 


Direct exchanges between Coordinating Authorities and service providers or 
between Coordinating Authorities and victims; 


The power of initiative of Coordinating Authorities to obtain the issuance of a 
detection order: 


The appointment of a contact officer for the EU Centre: 


The appointment of a representative of the Coordinating Authorities to sit on the 
Board of Directors; 


The drafting of an annual activity report. 
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Coordination at EU level entails (i) channelling of information gathered in their Member State of 
establishment to other Coordinating Authorities and the EU Centre, (ii) cooperating with these 
authorities, as well as with the Commission, and (iii) dispatching the information coming from the 
EU Centre and other Coordinating Authorities to other competent authorities in their Member State 
of establishment. In particular, the following tasks are reserved for Coordinating Authorities: 


© Coordinating with Commission and EU Centre for the issuance of guidelines on detection 
and reporting under Articles 11 and 12. 


© Receiving copies of cross-border removal orders from Coordinating Authority of issuing 
Member State (14(a)(1)). 


oO Transmitting copy of final removal, blocking and delisting orders issued in their Member 
State to all other Competent Authorities and EU Centre 


© Submitting items of materials, transeripts extracts of written conversations and exact 
uniform resource locators to the EU Centre in accordance with Article 36(1), as well as 
providing further clarifications and information to the EU Centre if needed, in accordance 
with Article 36(2). 


© Submitting requests for cross border cooperation in accordance with Article 37(1), receiving 
the Commission recommendations in line with the same paragraph and communicating the 
outcome of the assessment of the suspected infringement in accordance with Article 37(4). 


© Participating in joint investigations in accordance with Article 38. 
oO Exchanging information with other Coordinating Authorities under Article 38a 


Oo Communicating with other Coordinating Authorities, the Commission, the EU Centre and 
other relevant Union agencies through the reliable and secure information sharing system 
referred to in Article 39(2). 


Oo Making available to the EU Centre the information referred in Article 83(2). 
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